Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 171 of 207
CVE-2015-5767P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5767 [MEDIUM] CVE-2015-5767: The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspeci
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.
nvd
CVE-2015-5765P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5765 [MEDIUM] CVE-2015-5765: The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspeci
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.
nvd
CVE-2015-3710P4MEDIUMCVSS 4.3≤ 8.32015-07-03
CVE-2015-3710 [MEDIUM] CWE-254 CVE-2015-3710: Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh op
Mail in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to trigger a refresh operation, and consequently cause a visit to an arbitrary web site, via a crafted HTML e-mail message.
nvd
CVE-2011-2855P4MEDIUMCVSS 6.8fixed in 5.12011-09-19
CVE-2011-2855 [MEDIUM] CWE-74 CVE-2011-2855: Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequen
Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2013-3948P4MEDIUMCVSS 4.3v6.1.32013-06-05
CVE-2013-3948 [MEDIUM] CWE-20 CVE-2013-3948: Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS
Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download-manifest itms-services:// URL that leverages an open redirect vulnerability within a trusted domain.
nvd
CVE-2016-7592P4MEDIUMCVSS 4.3≤ 10.1.12017-02-20
CVE-2016-7592 [MEDIUM] CWE-200 CVE-2016-7592: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.
nvd
CVE-2014-1345P4MEDIUMCVSS 4.3≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1345 [MEDIUM] CVE-2014-1345: WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properl
WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2015-3758P4MEDIUMCVSS 4.3≤ 8.42015-08-16
CVE-2015-3758 [MEDIUM] CWE-20 CVE-2015-3758: UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation req
UIKit WebView in Apple iOS before 8.4.1 allows attackers to bypass an intended user-confirmation requirement and initiate arbitrary FaceTime calls via an app that provides a crafted URL.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5≥ 2.0, < 4.02009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2010-3827P4MEDIUMCVSS 4.3≤ 4.1v1.0.0+27 more2010-11-26
CVE-2010-3827 [MEDIUM] CWE-20 CVE-2010-3827: Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile
Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via unspecified vectors.
nvd
CVE-2020-3887P4MEDIUMCVSS 4.3fixed in 13.42020-04-01
CVE-2020-3887 [MEDIUM] CVE-2020-3887: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.
nvd
CVE-2025-43430P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43430 [MEDIUM] CWE-20 CVE-2025-43430: This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2017-13873P4MEDIUMCVSS 4.3fixed in 11.02018-04-03
CVE-2017-13873 [MEDIUM] CWE-200 CVE-2017-13873: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive network-activity information about arbitrary apps via a crafted app.
nvd
CVE-2025-43535P4MEDIUMCVSS 4.3fixed in 18.7.3≥ 26.0, < 26.22025-12-17
CVE-2025-43535 [MEDIUM] CVE-2025-43535: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43432P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43432 [MEDIUM] CWE-416 CVE-2025-43432: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43501P4MEDIUMCVSS 4.3fixed in 18.7.3≥ 26.0, < 26.22025-12-17
CVE-2025-43501 [MEDIUM] CWE-787 CVE-2025-43501: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 2
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-20664P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-20664 [MEDIUM] CWE-787 CVE-2026-20664: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43435P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43435 [MEDIUM] CWE-119 CVE-2025-43435: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43443P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43443 [MEDIUM] CVE-2025-43443: This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iP
This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28859P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-28859 [MEDIUM] CWE-125 CVE-2026-28859: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.
nvd