Apple iOS vulnerabilities
4,109 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,109
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL335HIGH1680MEDIUM1805LOW289
Vulnerabilities
Page 17 of 206
CVE-2018-4407P2HIGHCVSS 8.8fixed in 12.02019-04-03
CVE-2018-4407 [HIGH] CWE-119 CVE-2018-4407: A memory corruption issue was addressed with improved validation. This issue affected versions prior
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2016-1720P3HIGHCVSS 7.8PoCfixed in 9.2.12016-02-01
CVE-2016-1720 [HIGH] CWE-119 CVE-2016-1720: IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to ga
IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-1721P3HIGHCVSS 7.8PoCfixed in 9.2.12016-02-01
CVE-2016-1721 [HIGH] CWE-119 CVE-2016-1721: The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2019-8663P3MEDIUMCVSS 5.3PoCfixed in 12.42019-12-18
CVE-2019-8663 [MEDIUM] CVE-2019-8663: This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6. A remote attacker may be able to leak memory.
nvd
CVE-2019-8690P3MEDIUMCVSS 6.1PoCfixed in 12.42019-12-18
CVE-2019-8690 [MEDIUM] CWE-79 CVE-2019-8690: A logic issue existed in the handling of document loads. This issue was addressed with improved stat
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site script
nvd
CVE-2017-2445P3MEDIUMCVSS 6.1PoC≤ 10.2.12017-04-02
CVE-2017-2445 [MEDIUM] CWE-79 CVE-2017-2445: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via crafted frame objects.
nvd
CVE-2017-2510P3MEDIUMCVSS 6.1PoC≤ 10.3.12017-05-22
CVE-2017-2510 [MEDIUM] CWE-79 CVE-2017-2510: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events.
nvd
CVE-2017-2504P3MEDIUMCVSS 6.1PoCfixed in 10.3.22017-05-22
CVE-2017-2504 [MEDIUM] CWE-79 CVE-2017-2504: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with WebKit Editor commands.
nvd
CVE-2017-6979P3HIGHCVSS 7.0PoC≤ 10.3.12017-05-22
CVE-2017-6979 [HIGH] CWE-362 CVE-2017-6979: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "IOSurface" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2016-1863P3HIGHCVSS 7.8PoCfixed in 9.3.32016-07-22
CVE-2016-1863 [HIGH] CWE-416 CVE-2016-1863: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4582 and CVE-2016-4653.
nvd
CVE-2017-2508P3MEDIUMCVSS 6.1PoC≤ 10.3.12017-05-22
CVE-2017-2508 [MEDIUM] CWE-79 CVE-2017-2508: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with container nodes.
nvd
CVE-2010-1813P3MEDIUMCVSS 6.8PoCfixed in 4.12010-09-09
CVE-2010-1813 [MEDIUM] CWE-119 CVE-2010-1813: WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbit
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outlines.
nvd
CVE-2016-7661P3HIGHCVSS 7.8PoC≤ 10.1.12017-02-20
CVE-2016-7661 [HIGH] CWE-264 CVE-2016-7661: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "Power Management" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.
nvd
CVE-2016-7637P3HIGHCVSS 7.8PoC≤ 10.1.12017-02-20
CVE-2016-7637 [HIGH] CWE-119 CVE-2016-7637: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-7660P3HIGHCVSS 7.8PoC≤ 10.1.12017-02-20
CVE-2016-7660 [HIGH] CWE-264 CVE-2016-7660: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.
nvd
CVE-2012-3748P3MEDIUMCVSS 5.1PoC≤ 6.0v1.0.0+39 more2012-11-03
CVE-2012-3748 [MEDIUM] CWE-362 CVE-2012-3748: Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers t
Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript arrays.
nvd
CVE-2017-2528P3MEDIUMCVSS 6.1PoC≤ 10.3.12017-05-22
CVE-2017-2528 [MEDIUM] CWE-79 CVE-2017-2528: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with cached frames.
nvd
CVE-2019-8591P3HIGHCVSS 7.1PoCfixed in 12.32019-12-18
CVE-2019-8591 [HIGH] CWE-843 CVE-2019-8591: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3,
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2015-1155P3MEDIUMCVSS 4.3PoC≤ 8.32015-05-08
CVE-2015-1155 [MEDIUM] CWE-264 CVE-2015-1155: The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files via a crafted web site.
nvd
CVE-2020-9839P3HIGHCVSS 7.0PoCfixed in 13.52020-06-09
CVE-2020-9839 [HIGH] CWE-362 CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
nvd