cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 180 of 207
CVE-2015-5859P4MEDIUMCVSS 4.3≤ 8.4.12015-11-22
CVE-2015-5859 [MEDIUM] CWE-200 CVE-2015-5859: The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly r The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS preload list during a Safari private-browsing session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2015-3721P4MEDIUMCVSS 4.3≤ 8.32015-07-03
CVE-2015-3721 [MEDIUM] CWE-200 CVE-2015-3721: The kernel in Apple iOS before 8.4 and OS X before 10.10.4 does not properly handle HFS parameters, The kernel in Apple iOS before 8.4 and OS X before 10.10.4 does not properly handle HFS parameters, which allows attackers to obtain sensitive memory-layout information via a crafted app.
nvd
CVE-2013-5152P4MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5152 [MEDIUM] CWE-20 CVE-2013-5152: Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web s Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
nvd
CVE-2025-43280P4MEDIUMCVSS 4.7fixed in 18.62025-10-15
CVE-2025-43280 [MEDIUM] CWE-940 CVE-2025-43280: The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6 The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail in Lockdown Mode.
nvd
CVE-2010-0038P4MEDIUMCVSS 4.6v1.0v1.0.0+20 more2010-02-03
CVE-2010-0038 [MEDIUM] CWE-399 CVE-2010-0038: Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.
nvd
CVE-2019-8827P4MEDIUMCVSS 4.3fixed in 13.22020-10-27
CVE-2019-8827 [MEDIUM] CVE-2019-8827: The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a
nvd
CVE-2026-28856P4MEDIUMCVSS 4.6fixed in 26.42026-03-25
CVE-2026-28856 [MEDIUM] CWE-284 CVE-2026-28856: The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26. The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, watchOS 26.4. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-43753P4MEDIUMCVSS 4.6fixed in 26.62026-07-27
CVE-2026-43753 [MEDIUM] CWE-125 CVE-2026-43753: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2013-3954P4MEDIUMCVSS 6.9≤ 6.1.4v1.0.0+46 more2013-06-05
CVE-2013-3954 [MEDIUM] CWE-20 CVE-2013-3954: The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate th The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2) obtain sensitive information from kernel heap memory via a certain size va
nvd
CVE-2026-64732P4MEDIUMCVSS 4.6fixed in 26.62026-07-27
CVE-2026-64732 [MEDIUM] CWE-284 CVE-2026-64732: This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.
nvd
CVE-2014-4368P4MEDIUMCVSS 6.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4368 [MEDIUM] CWE-264 CVE-2014-4368: The Accessibility subsystem in Apple iOS before 8 allows attackers to interfere with screen locking The Accessibility subsystem in Apple iOS before 8 allows attackers to interfere with screen locking via vectors related to AssistiveTouch events.
nvd
CVE-2019-8898P4MEDIUMCVSS 4.3fixed in 13.32020-10-27
CVE-2019-8898 [MEDIUM] CVE-2019-8898: An information disclosure issue existed in the handling of the Storage Access API. This issue was ad An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
nvd
CVE-2025-43368P4MEDIUMCVSS 4.3fixed in 26.02025-09-15
CVE-2025-43368 [MEDIUM] CWE-416 CVE-2025-43368: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-31239P4MEDIUMCVSS 4.3fixed in 18.52025-05-12
CVE-2025-31239 [MEDIUM] CWE-416 CVE-2025-31239: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to an unexpected app termination.
nvd
CVE-2025-43421P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43421 [MEDIUM] CWE-125 CVE-2025-43421: Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2024-54535P4MEDIUMCVSS 4.3fixed in 18.12025-01-15
CVE-2024-54535 [MEDIUM] CWE-22 CVE-2024-54535: A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An attacker with access to calendar data could also read reminders.
nvd
CVE-2025-43503P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43503 [MEDIUM] CWE-290 CVE-2025-43503: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Visiting a malicious website may lead to user interface spoofing.
nvd
CVE-2026-43708P4MEDIUMCVSS 4.3fixed in 26.5.22026-06-29
CVE-2026-43708 [MEDIUM] CWE-20 CVE-2026-43708: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2026-28861P4MEDIUMCVSS 4.3fixed in 18.7.7≥ 26.0, < 26.42026-03-25
CVE-2026-28861 [MEDIUM] CWE-79 CVE-2026-28861: A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.
nvd
CVE-2026-28917P4MEDIUMCVSS 4.3fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28917 [MEDIUM] CWE-20 CVE-2026-28917: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
Apple iOS vulnerabilities | cvebase