cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 179 of 207
CVE-2024-44183P4MEDIUMCVSS 5.5fixed in 17.72024-09-17
CVE-2024-44183 [MEDIUM] CWE-400 CVE-2024-44183: A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to cause a denial-of-service.
nvd
CVE-2024-23220P4MEDIUMCVSS 5.5fixed in 17.42024-03-08
CVE-2024-23220 [MEDIUM] CVE-2024-23220: The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.4 and iPadOS The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to fingerprint the user.
nvd
CVE-2023-32400P4MEDIUMCVSS 5.5fixed in 16.52023-06-23
CVE-2023-32400 [MEDIUM] CWE-281 CVE-2023-32400: This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watc This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
nvd
CVE-2025-31226P4MEDIUMCVSS 5.5fixed in 18.52025-05-12
CVE-2025-31226 [MEDIUM] CWE-400 CVE-2025-31226: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, i A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted image may lead to a denial-of-service.
nvd
CVE-2026-28852P4MEDIUMCVSS 5.5fixed in 18.7.7≥ 26.0, < 26.42026-03-25
CVE-2026-28852 [MEDIUM] CWE-20 CVE-2026-28852: A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause a denial-of-service.
nvd
CVE-2011-1418P4MEDIUMCVSS 5.0≤ 4.2v1.0.0+28 more2011-03-11
CVE-2011-1418 [MEDIUM] CWE-200 CVE-2011-1418: The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementat The stateless address autoconfiguration (aka SLAAC) functionality in the IPv6 networking implementation in Apple iOS before 4.3 and Apple TV before 4.2 places the MAC address into the IPv6 address, which makes it easier for remote IPv6 servers to track users by logging source IPv6 addresses.
nvd
CVE-2023-28185P4MEDIUMCVSS 5.5≥ 15.0, < 15.7.4≥ 16.0, < 16.42024-01-10
CVE-2023-28185 [MEDIUM] CWE-190 CVE-2023-28185: An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16. An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4, watchOS 9.4, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. An app may be able to cause a denial-of-service.
nvd
CVE-2025-24184P4MEDIUMCVSS 5.5fixed in 18.32025-05-19
CVE-2025-24184 [MEDIUM] CVE-2025-24184: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.
nvd
CVE-2026-20654P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20654 [MEDIUM] CWE-119 CVE-2026-20654: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
nvd
CVE-2012-3724P4MEDIUMCVSS 5.0≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3724 [MEDIUM] CWE-200 CVE-2012-3724: CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows r CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed URL.
nvd
CVE-2010-1181P4MEDIUMCVSS 4.3v3.1.32010-03-29
CVE-2010-1181 [MEDIUM] CWE-20 CVE-2010-1181: Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a MARQUEE element.
nvd
CVE-2025-30434P4MEDIUMCVSS 5.0fixed in 18.42025-03-31
CVE-2025-30434 [MEDIUM] CWE-79 CVE-2025-30434: The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.
nvd
CVE-2016-1728P4MEDIUMCVSS 4.3≤ 9.22016-02-01
CVE-2016-1728 [MEDIUM] CWE-200 CVE-2016-1728: The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mi The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain sensitive browser-history information via a crafted web site.
nvd
CVE-2018-4440P4MEDIUMCVSS 4.3fixed in 12.1.12019-04-03
CVE-2018-4440 [MEDIUM] CWE-20 CVE-2018-4440: A logic issue was addressed with improved state management. This issue affected versions prior to iO A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvd
CVE-2024-40829P4MEDIUMCVSS 4.6fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40829 [MEDIUM] CWE-416 CVE-2024-40829: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, i The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker may be able to view restricted content from the lock screen.
nvd
CVE-2022-32919P4MEDIUMCVSS 4.7fixed in 16.22024-01-10
CVE-2022-32919 [MEDIUM] CWE-1021 CVE-2022-32919: The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2015-7058P4MEDIUMCVSS 4.3≤ 9.12015-12-11
CVE-2015-7058 [MEDIUM] CWE-200 CVE-2015-7058: Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 improperly validate keychain item ACL Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 improperly validate keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.
nvd
CVE-2015-3782P4MEDIUMCVSS 4.3≤ 8.42015-08-16
CVE-2015-3782 [MEDIUM] CWE-200 CVE-2015-3782: CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud user CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud user record associated with a previous user's login session via a crafted app.
nvd
CVE-2015-3766P4MEDIUMCVSS 4.3≤ 8.42015-08-16
CVE-2015-3766 [MEDIUM] CWE-200 CVE-2015-3766: The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the mach_por The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the mach_port_space_info interface, which allows attackers to obtain sensitive memory-layout information via a crafted app.
nvd
CVE-2014-4383P4MEDIUMCVSS 4.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4383 [MEDIUM] CWE-20 CVE-2014-4383: The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device's update status via a crafted Last-Modified HTTP response header.
nvd
Apple iOS vulnerabilities | cvebase