Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 18 of 207
CVE-2020-9839P3HIGHCVSS 7.0PoCfixed in 13.52020-06-09
CVE-2020-9839 [HIGH] CWE-362 CVE-2020-9839: A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.
nvd
CVE-2014-1287P3HIGHCVSS 7.2PoC≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1287 [HIGH] CWE-119 CVE-2014-1287: USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to ex
USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.
nvd
CVE-2016-4622P3HIGHCVSS 8.8fixed in 9.3.32016-07-22
CVE-2016-4622 [HIGH] CVE-2016-4622: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.
nvd
CVE-2015-7036P3HIGHCVSS 7.5≤ 8.32015-11-22
CVE-2015-7036 [HIGH] CWE-20 CVE-2015-7036: The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allo
The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted pointer value in the second argument.
nvd
CVE-2015-1126P3MEDIUMCVSS 4.3PoC≤ 8.22015-04-10
CVE-2015-1126 [MEDIUM] CWE-20 CVE-2015-1126: WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x bef
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors.
nvd
CVE-2022-26711P3CRITICALCVSS 9.8fixed in 15.52022-05-26
CVE-2022-26711 [CRITICAL] CWE-190 CVE-2022-26711: An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS
An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2022-32839P3CRITICALCVSS 9.8fixed in 15.62022-08-24
CVE-2022-32839 [CRITICAL] CWE-119 CVE-2022-32839: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, mac
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.
nvd
CVE-2015-6988P3CRITICALCVSS 10.0≤ 9.0.22015-10-23
CVE-2015-6988 [CRITICAL] CVE-2015-6988: The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data s
The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data structure, which allows remote attackers to execute arbitrary code via vectors involving an unknown network-connectivity requirement.
nvd
CVE-2015-7084P3HIGHCVSS 7.2PoC≤ 9.12015-12-11
CVE-2015-7084 [HIGH] CVE-2015-7084: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.
nvd
CVE-2020-9895P3CRITICALCVSS 9.8fixed in 13.62020-10-16
CVE-2020-9895 [CRITICAL] CWE-416 CVE-2020-9895: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2018-20506P3HIGHCVSS 8.1fixed in 12.1.32019-04-03
CVE-2018-20506 [HIGH] CVE-2018-20506: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use ca
nvd
CVE-2022-42842P3CRITICALCVSS 9.8fixed in 16.22022-12-15
CVE-2022-42842 [CRITICAL] CWE-787 CVE-2022-42842: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monte
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.
nvd
CVE-2022-42808P3CRITICALCVSS 9.8fixed in 16.12022-11-01
CVE-2022-42808 [CRITICAL] CWE-787 CVE-2022-42808: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvO
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.
nvd
CVE-2022-22629P3HIGHCVSS 8.8fixed in 15.42022-09-23
CVE-2022-22629 [HIGH] CWE-787 CVE-2022-22629: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-32941P3CRITICALCVSS 9.8fixed in 15.7.1v16.02022-11-01
CVE-2022-32941 [CRITICAL] CWE-120 CVE-2022-32941: The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15
The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A buffer overflow may result in arbitrary code execution.
nvd
CVE-2023-38598P3CRITICALCVSS 9.8fixed in 15.7.8≥ 16.0, < 16.62023-07-28
CVE-2023-38598 [CRITICAL] CWE-416 CVE-2023-38598: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-36495P3CRITICALCVSS 9.8fixed in 15.7.8≥ 16.0, < 16.62023-07-28
CVE-2023-36495 [CRITICAL] CWE-190 CVE-2023-36495: An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2011-3026P3MEDIUMCVSS 6.8fixed in 6.02012-02-16
CVE-2011-3026 [MEDIUM] CWE-190 CVE-2011-3026: Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
nvd
CVE-2022-32792P3HIGHCVSS 8.8fixed in 15.62022-09-23
CVE-2022-32792 [HIGH] CWE-787 CVE-2022-32792: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-42852P3HIGHCVSS 8.8fixed in 16.7.2≥ 17.0, < 17.12023-10-25
CVE-2023-42852 [HIGH] CVE-2023-42852: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, w
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
nvd