Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 170 of 207
CVE-2025-24220P4MEDIUMCVSS 5.5fixed in 18.42025-05-12
CVE-2025-24220 [MEDIUM] CWE-200 CVE-2025-24220: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able to read a persistent device identifier.
nvd
CVE-2024-23205P4MEDIUMCVSS 5.5fixed in 17.42024-03-08
CVE-2024-23205 [MEDIUM] CWE-922 CVE-2024-23205: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access sensitive user data.
nvd
CVE-2024-44263P4MEDIUMCVSS 5.5fixed in 18.12024-10-28
CVE-2024-44263 [MEDIUM] CWE-922 CVE-2024-44263: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to access user-sensitive data.
nvd
CVE-2023-23503P4MEDIUMCVSS 5.5fixed in 15.7.3≥ 16.0, < 16.32023-02-27
CVE-2023-23503 [MEDIUM] CWE-288 CVE-2023-23503: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-32855P4MEDIUMCVSS 5.5fixed in 15.62023-02-27
CVE-2022-32855 [MEDIUM] CWE-200 CVE-2022-32855: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen.
nvd
CVE-2022-46710P4MEDIUMCVSS 5.5fixed in 16.22024-01-10
CVE-2022-46710 [MEDIUM] CWE-841 CVE-2022-46710: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, m
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Location data may be shared via iCloud links even if Location metadata is disabled via the Share Sheet.
nvd
CVE-2023-40437P4MEDIUMCVSS 5.5fixed in 16.62024-01-10
CVE-2023-40437 [MEDIUM] CVE-2023-40437: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to read sensitive location information.
nvd
CVE-2023-40438P4MEDIUMCVSS 5.5fixed in 16.72024-01-10
CVE-2023-40438 [MEDIUM] CWE-379 CVE-2023-40438: An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonom
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to access edited photos saved to a temporary directory.
nvd
CVE-2023-42872P4MEDIUMCVSS 5.5fixed in 17.02024-01-10
CVE-2023-42872 [MEDIUM] CVE-2023-42872: The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14,
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to access sensitive user data.
nvd
CVE-2023-42839P4MEDIUMCVSS 5.5fixed in 17.12024-02-21
CVE-2023-42839 [MEDIUM] CWE-922 CVE-2023-42839: This issue was addressed with improved state management. This issue is fixed in tvOS 17.1, watchOS 1
This issue was addressed with improved state management. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An app may be able to access sensitive user data.
nvd
CVE-2026-20638P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20638 [MEDIUM] CWE-284 CVE-2026-20638: A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions.
nvd
CVE-2026-43744P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43744 [MEDIUM] CWE-787 CVE-2026-43744: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing an audio stream in a maliciously crafted media file may terminate the process.
nvd
CVE-2026-64754P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64754 [MEDIUM] CWE-787 CVE-2026-64754: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service.
nvd
CVE-2026-64718P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64718 [MEDIUM] CWE-416 CVE-2026-64718: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-30428P4MEDIUMCVSS 5.4fixed in 18.42025-03-31
CVE-2025-30428 [MEDIUM] CWE-305 CVE-2025-30428: This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.
nvd
CVE-2017-7083P4MEDIUMCVSS 4.9≤ 10.3.32017-10-23
CVE-2017-7083 [MEDIUM] CWE-20 CVE-2017-7083: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "CFNetwork Proxies" component. It allows remote attackers to cause a denial of service.
nvd
CVE-2014-1276P4MEDIUMCVSS 5.0≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1276 [MEDIUM] CWE-264 CVE-2014-1276: IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks a
IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that accesses an IOKit framework interface.
nvd
CVE-2026-28994P4MEDIUMCVSS 5.3fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28994 [MEDIUM] CWE-416 CVE-2026-28994: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Wi-Fi pac
nvd
CVE-2015-3807P4MEDIUMCVSS 4.3≤ 8.4≤ 9.12015-08-17
CVE-2015-3807 [MEDIUM] CWE-119 CVE-2015-3807: libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitiv
libxml2 in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted XML document.
nvd
CVE-2015-3755P4MEDIUMCVSS 4.3fixed in 8.4.12015-08-16
CVE-2015-3755 [MEDIUM] CWE-254 CVE-2015-3755: WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8
WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, allows remote attackers to spoof the user interface via a malformed URL.
nvd