Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 175 of 207
CVE-2023-32399P4MEDIUMCVSS 5.5fixed in 16.52023-06-23
CVE-2023-32399 [MEDIUM] CWE-276 CVE-2023-32399: The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to read sensitive location information.
nvd
CVE-2023-28178P4MEDIUMCVSS 5.5fixed in 16.42023-05-08
CVE-2023-28178 [MEDIUM] CVE-2023-28178: A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, iOS
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-42792P4MEDIUMCVSS 5.5fixed in 16.12023-06-23
CVE-2022-42792 [MEDIUM] CWE-203 CVE-2022-42792: This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 1
This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive location information
nvd
CVE-2024-54560P4MEDIUMCVSS 5.5fixed in 18.02025-03-10
CVE-2024-54560 [MEDIUM] CWE-269 CVE-2024-54560: A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be able to modify other apps without having App Management permission.
nvd
CVE-2025-24111P4MEDIUMCVSS 5.5fixed in 18.32025-05-12
CVE-2025-24111 [MEDIUM] CWE-119 CVE-2025-24111: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.
nvd
CVE-2022-32918P4MEDIUMCVSS 5.5fixed in 16.02022-11-01
CVE-2022-32918 [MEDIUM] CWE-284 CVE-2022-32918: This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy preferences.
nvd
CVE-2023-32438P4MEDIUMCVSS 5.5fixed in 16.32023-09-06
CVE-2023-32438 [MEDIUM] CVE-2023-32438: This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in tvOS 16.3, macOS Ventura 13.2, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.
nvd
CVE-2025-31245P4MEDIUMCVSS 5.5fixed in 18.52025-05-12
CVE-2025-31245 [MEDIUM] CWE-400 CVE-2025-31245: The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5. An app may be able to cause unexpected system termination.
nvd
CVE-2024-44198P4MEDIUMCVSS 5.5fixed in 18.02024-09-17
CVE-2024-44198 [MEDIUM] CWE-190 CVE-2024-44198: An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 a
An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43398P4MEDIUMCVSS 5.5fixed in 26.12025-11-04
CVE-2025-43398 [MEDIUM] CWE-119 CVE-2025-43398: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination.
nvd
CVE-2025-43447P4MEDIUMCVSS 5.5fixed in 26.12025-11-04
CVE-2025-43447 [MEDIUM] CWE-787 CVE-2025-43447: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2023-41069P4MEDIUMCVSS 5.5fixed in 17.02024-01-10
CVE-2023-41069 [MEDIUM] CWE-290 CVE-2023-41069: This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 an
This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to look like the enrolled user may authenticate via Face ID.
nvd
CVE-2025-43282P4MEDIUMCVSS 5.5fixed in 18.62025-10-15
CVE-2025-43282 [MEDIUM] CWE-415 CVE-2025-43282: A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 a
A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-20621P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20621 [MEDIUM] CWE-119 CVE-2026-20621: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43816P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43816 [MEDIUM] CWE-787 CVE-2026-43816: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64693P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64693 [MEDIUM] CWE-843 CVE-2026-64693: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadO
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may lead to a denial-of-service.
nvd
CVE-2026-43739P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43739 [MEDIUM] CWE-787 CVE-2026-43739: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2016-7651P4MEDIUMCVSS 5.3≤ 10.1.12017-02-20
CVE-2016-7651 [MEDIUM] CWE-285 CVE-2016-7651: An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1
An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local users to bypass intended authorization restrictions by leveraging the mishandling of an app uninstall.
nvd
CVE-2015-5788P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5788 [MEDIUM] CWE-200 CVE-2015-5788: The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Or
The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.
nvd
CVE-2021-30884P4MEDIUMCVSS 4.7fixed in 15.02021-08-24
CVE-2021-30884 [MEDIUM] CVE-2021-30884: The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS
The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Visiting a maliciously crafted website may reveal a user's browsing history.
nvd