cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 167 of 207
CVE-2025-46305P4MEDIUMCVSS 5.7fixed in 18.7.52026-02-11
CVE-2025-46305 [MEDIUM] CWE-119 CVE-2025-46305: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.
nvd
CVE-2025-46304P4MEDIUMCVSS 5.7fixed in 18.7.52026-02-11
CVE-2025-46304 [MEDIUM] CWE-400 CVE-2025-46304: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.
nvd
CVE-2018-4433P4MEDIUMCVSS 5.5fixed in 12.02020-10-27
CVE-2018-4433 [MEDIUM] CVE-2018-4433: A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojav A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, watchOS 5, iOS 12, tvOS 12, macOS Mojave 10.14. A malicious application may be able to modify protected parts of the file system.
nvd
CVE-2023-42883P4MEDIUMCVSS 5.5fixed in 16.7.3≥ 17.0, < 17.22023-12-12
CVE-2023-42883 [MEDIUM] CVE-2023-42883: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Son The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.
nvd
CVE-2021-1781P4MEDIUMCVSS 5.5fixed in 14.42021-04-02
CVE-2021-1781 [MEDIUM] CVE-2021-1781: A privacy issue existed in the handling of Contact cards. This was addressed with improved state man A privacy issue existed in the handling of Contact cards. This was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A malicious application may be able to leak sensitive user information.
nvd
CVE-2018-4173P4MEDIUMCVSS 5.5fixed in 11.32018-04-13
CVE-2018-4173 [MEDIUM] CWE-269 CVE-2018-4173: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.
nvd
CVE-2012-3743P4MEDIUMCVSS 5.0≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3743 [MEDIUM] CWE-264 CVE-2012-3743: The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sensitive information via a crafted app that reads log files.
nvd
CVE-2012-3744P4MEDIUMCVSS 5.0≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3744 [MEDIUM] CVE-2012-3744: Telephony in Apple iOS before 6 uses an SMS message's return address as the displayed sender address Telephony in Apple iOS before 6 uses an SMS message's return address as the displayed sender address, which allows remote attackers to spoof text communication via a message in which the return address does not match the originating address.
nvd
CVE-2011-1190P4MEDIUMCVSS 5.0fixed in 5.02011-03-11
CVE-2011-1190 [MEDIUM] CWE-200 CVE-2011-1190: The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypas The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2020-27929P4MEDIUMCVSS 5.5fixed in 12.4.92020-12-08
CVE-2020-27929 [MEDIUM] CVE-2020-27929: A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.4.9. A user may send video in Group FaceTime calls without knowing that they have done so.
nvd
CVE-2022-32828P4MEDIUMCVSS 5.5fixed in 15.62022-09-23
CVE-2022-32828 [MEDIUM] CVE-2022-32828: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15 The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
nvd
CVE-2018-4225P4MEDIUMCVSS 5.5fixed in 11.42018-06-08
CVE-2018-4225 [MEDIUM] CWE-20 CVE-2018-4225: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended restrictions on Keychain state mo
nvd
CVE-2018-4226P4MEDIUMCVSS 5.5fixed in 11.42018-06-08
CVE-2018-4226 [MEDIUM] CWE-200 CVE-2018-4226: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended restrictions on the reading of s
nvd
CVE-2024-27841P4MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27841 [MEDIUM] CWE-284 CVE-2024-27841: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.
nvd
CVE-2024-23241P4MEDIUMCVSS 5.5fixed in 17.42024-03-08
CVE-2024-23241 [MEDIUM] CWE-922 CVE-2024-23241: This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4. An app may be able to leak sensitive user information.
nvd
CVE-2025-24163P4MEDIUMCVSS 5.5fixed in 18.32025-01-27
CVE-2025-24163 [MEDIUM] CVE-2025-24163: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 1 The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tvOS 18.3, tvOS 18.4, visionOS 2.3, visionOS 2.4, watchOS 11.3, watchOS 11.4. Parsing a file may lead to an unexpected app termination.
nvd
CVE-2020-7463P4MEDIUMCVSS 5.5fixed in 14.52021-03-26
CVE-2020-7463 [MEDIUM] CWE-416 CVE-2020-7463: In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELE In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour
nvd
CVE-2024-40806P4MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40806 [MEDIUM] CWE-125 CVE-2024-40806: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2020-9969P4MEDIUMCVSS 5.5fixed in 14.02020-12-08
CVE-2020-9969 [MEDIUM] CVE-2020-9969: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. A local user may be able to view senstive user information.
nvd
CVE-2023-38596P4MEDIUMCVSS 5.5fixed in 17.02023-09-27
CVE-2023-38596 [MEDIUM] CVE-2023-38596: The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 17 The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may fail to enforce App Transport Security.
nvd
Apple iOS vulnerabilities | cvebase