Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 181 of 207
CVE-2025-46316P4MEDIUMCVSS 4.3fixed in 26.12026-01-28
CVE-2025-46316 [MEDIUM] CWE-125 CVE-2025-46316: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory.
nvd
CVE-2026-28871P4MEDIUMCVSS 4.3fixed in 18.7.7≥ 26.0, < 26.42026-03-25
CVE-2026-28871 [MEDIUM] CWE-79 CVE-2026-28871: A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and
A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.
nvd
CVE-2023-38614P4MEDIUMCVSS 4.3fixed in 17.02025-04-11
CVE-2023-38614 [MEDIUM] CWE-269 CVE-2023-38614: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iP
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.
nvd
CVE-2014-1272P4MEDIUMCVSS 6.3≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1272 [MEDIUM] CWE-59 CVE-2014-1272: CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local us
CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink.
nvd
CVE-2013-5145P4MEDIUMCVSS 6.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5145 [MEDIUM] CWE-264 CVE-2013-5145: kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messag
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message.
nvd
CVE-2016-7665P4MEDIUMCVSS 5.5≤ 10.1.12017-02-20
CVE-2016-7665 [MEDIUM] CWE-20 CVE-2016-7665: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Graphics Driver" component, which allows remote attackers to cause a denial of service via a crafted video.
nvd
CVE-2016-1752P4MEDIUMCVSS 5.5fixed in 9.32016-03-24
CVE-2016-1752 [MEDIUM] CWE-20 CVE-2016-1752: The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2012-0641P4MEDIUMCVSS 5.0fixed in 5.12012-03-08
CVE-2012-0641 [MEDIUM] CVE-2012-0641: CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs
CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-2011-3447.
nvd
CVE-2018-4216P4MEDIUMCVSS 5.5fixed in 11.4.12019-04-03
CVE-2018-4216 [MEDIUM] CVE-2018-4216: A logic issue existed in the handling of call URLs. This issue was addressed with improved state man
A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1.
nvd
CVE-2011-3234P4MEDIUMCVSS 5.0fixed in 5.02011-09-19
CVE-2011-3234 [MEDIUM] CWE-125 CVE-2011-3234: Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to c
Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2018-4395P4MEDIUMCVSS 5.5fixed in 12.02019-04-03
CVE-2018-4395 [MEDIUM] CWE-20 CVE-2018-4395: This issue was addressed with improved checks. This issue affected versions prior to iOS 12, macOS M
This issue was addressed with improved checks. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2016-4628P4MEDIUMCVSS 5.5≤ 9.3.22016-07-22
CVE-2016-4628 [MEDIUM] CWE-125 CVE-2016-4628: IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain
IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2020-27925P4MEDIUMCVSS 5.5fixed in 14.22020-12-08
CVE-2020-27925 [MEDIUM] CVE-2020-27925: An issue existed in the handling of incoming calls. The issue was addressed with additional state ch
An issue existed in the handling of incoming calls. The issue was addressed with additional state checks. This issue is fixed in iOS 14.2 and iPadOS 14.2. A user may answer two calls simultaneously without indication they have answered a second call.
nvd
CVE-2024-23201P4MEDIUMCVSS 5.5fixed in 17.32024-03-08
CVE-2024-23201 [MEDIUM] CWE-276 CVE-2024-23201: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-of-service.
nvd
CVE-2022-32946P4MEDIUMCVSS 5.5fixed in 16.12022-11-01
CVE-2022-32946 [MEDIUM] CWE-284 CVE-2022-32946: This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16.
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.
nvd
CVE-2015-1090P4MEDIUMCVSS 5.0≤ 8.22015-04-10
CVE-2015-1090 [MEDIUM] CWE-200 CVE-2015-1090: CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state inform
CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file.
nvd
CVE-2025-43355P4MEDIUMCVSS 5.5fixed in 18.72025-09-15
CVE-2025-43355 [MEDIUM] CWE-843 CVE-2025-43355: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43295P4MEDIUMCVSS 5.5fixed in 18.72025-09-15
CVE-2025-43295 [MEDIUM] CWE-400 CVE-2025-43295: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 an
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43299P4MEDIUMCVSS 5.5fixed in 18.72025-09-15
CVE-2025-43299 [MEDIUM] CWE-20 CVE-2025-43299: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 an
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to cause a denial-of-service.
nvd
CVE-2023-38593P4MEDIUMCVSS 5.5fixed in 15.7.8≥ 16.0, < 16.62023-07-27
CVE-2023-38593 [MEDIUM] CVE-2023-38593: A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to cause a denial-of-service.
nvd