Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 168 of 207
CVE-2018-4380P4MEDIUMCVSS 5.5fixed in 12.12019-04-03
CVE-2018-4380 [MEDIUM] CWE-200 CVE-2018-4380: A lock screen issue allowed access to photos and contacts on a locked device. This issue was address
A lock screen issue allowed access to photos and contacts on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.0.1.
nvd
CVE-2022-42866P4MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42866 [MEDIUM] CWE-200 CVE-2022-42866: The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.
nvd
CVE-2019-8546P4MEDIUMCVSS 5.5fixed in 12.22019-12-18
CVE-2019-8546 [MEDIUM] CVE-2019-8546: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2,
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A local user may be able to view sensitive user information.
nvd
CVE-2020-9772P4MEDIUMCVSS 5.5fixed in 13.42020-10-22
CVE-2020-9772 [MEDIUM] CVE-2020-9772: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2022-22655P4MEDIUMCVSS 5.5≥ 15.0, < 15.42023-08-14
CVE-2022-22655 [MEDIUM] CVE-2022-22655: An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Montere
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4. An app may be able to leak sensitive user information.
nvd
CVE-2022-42865P4MEDIUMCVSS 5.5fixed in 16.22022-12-15
CVE-2022-42865 [MEDIUM] CWE-284 CVE-2022-42865: This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
nvd
CVE-2019-8704P4MEDIUMCVSS 5.5fixed in 13.02019-12-18
CVE-2019-8704 [MEDIUM] CWE-287 CVE-2019-8704: An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.
nvd
CVE-2020-3874P4MEDIUMCVSS 5.3fixed in 13.3.12020-02-27
CVE-2020-3874 [MEDIUM] CWE-212 CVE-2020-3874: An issued existed in the naming of screenshots. The issue was corrected with improved naming. This i
An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.
nvd
CVE-2021-1822P4MEDIUMCVSS 5.5fixed in 14.52021-09-08
CVE-2021-1822 [MEDIUM] CVE-2021-1822: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.
nvd
CVE-2019-8793P4MEDIUMCVSS 5.5fixed in 13.22019-12-18
CVE-2019-8793 [MEDIUM] CVE-2019-8793: A consistency issue existed in deciding when to show the screen recording indicator. The issue was r
A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.
nvd
CVE-2021-30811P4MEDIUMCVSS 5.5fixed in 15.02021-10-19
CVE-2021-30811 [MEDIUM] CVE-2021-30811: This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS
This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker may be able to read sensitive information.
nvd
CVE-2017-7113P4MEDIUMCVSS 5.5fixed in 11.12017-11-13
CVE-2017-7113 [MEDIUM] CWE-200 CVE-2017-7113: An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "UIKit" component. It allows attackers to bypass intended read restrictions for secure text fields via vectors involving a focus-change event.
nvd
CVE-2024-23297P4MEDIUMCVSS 5.5fixed in 17.42024-03-08
CVE-2024-23297 [MEDIUM] CVE-2024-23297: The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to access private information.
nvd
CVE-2021-1836P4MEDIUMCVSS 5.5fixed in 14.52021-09-08
CVE-2021-1836 [MEDIUM] CWE-269 CVE-2021-1836: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A local user may be able to create or modify privileged files.
nvd
CVE-2022-32858P4MEDIUMCVSS 5.5fixed in 16.02022-11-01
CVE-2022-32858 [MEDIUM] CWE-200 CVE-2022-32858: The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura
The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leak sensitive kernel state.
nvd
CVE-2021-30967P4MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30967 [MEDIUM] CVE-2021-30967: Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS
Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPadOS 15.2. A local attacker may be able to read sensitive information.
nvd
CVE-2023-32354P4MEDIUMCVSS 5.5fixed in 16.52023-06-23
CVE-2023-32354 [MEDIUM] CWE-125 CVE-2023-32354: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, iOS 16.5 and iPadOS 16.5. An app may be able to disclose kernel memory.
nvd
CVE-2021-1848P4MEDIUMCVSS 5.5fixed in 14.52021-09-08
CVE-2021-1848 [MEDIUM] CVE-2021-1848: The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5.
The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.
nvd
CVE-2021-30871P4MEDIUMCVSS 5.5fixed in 14.72021-08-24
CVE-2021-30871 [MEDIUM] CVE-2021-30871: This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS
This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS Big Sur 11.5. A local attacker may be able to access analytics data.
nvd
CVE-2025-24202P4MEDIUMCVSS 5.5fixed in 18.42025-03-31
CVE-2025-24202 [MEDIUM] CWE-284 CVE-2025-24202: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPad
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
nvd