cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 182 of 207
CVE-2025-31202P4MEDIUMCVSS 5.5fixed in 18.42025-04-29
CVE-2025-31202 [MEDIUM] CWE-476 CVE-2025-31202: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2026-64724P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64724 [MEDIUM] CWE-400 CVE-2026-64724: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2026-43817P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43817 [MEDIUM] CWE-125 CVE-2026-43817: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2009-1702P4MEDIUMCVSS 4.3v1.0.0v1.0.1+15 more2009-06-10
CVE-2009-1702 [MEDIUM] CWE-79 CVE-2009-1702: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper handling of Location and History objects.
nvd
CVE-2010-1407P4MEDIUMCVSS 4.3≤ 3.2v1.0.0+18 more2010-06-22
CVE-2010-1407 [MEDIUM] CWE-200 CVE-2010-1407: WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.re WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.
nvd
CVE-2018-4278P4MEDIUMCVSS 4.3fixed in 11.4.12019-01-11
CVE-2018-4278 [MEDIUM] CVE-2018-4278: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
nvd
CVE-2021-1865P4MEDIUMCVSS 5.0fixed in 14.52021-09-08
CVE-2021-1865 [MEDIUM] CWE-312 CVE-2021-1865: An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed i An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.
nvd
CVE-2010-1776P4MEDIUMCVSS 4.8v2.1v2.1.1+7 more2017-04-24
CVE-2010-1776 [MEDIUM] CWE-254 CVE-2010-1776: Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod t Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to wipe the device.
nvd
CVE-2012-0588P4MEDIUMCVSS 4.3fixed in 5.12012-03-08
CVE-2012-0588 [MEDIUM] CVE-2012-0588: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote a Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0587, and CVE-2012-0589.
nvd
CVE-2012-0589P4MEDIUMCVSS 4.3fixed in 5.12012-03-08
CVE-2012-0589 [MEDIUM] CVE-2012-0589: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote a Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0587, and CVE-2012-0588.
nvd
CVE-2012-0587P4MEDIUMCVSS 4.3fixed in 5.12012-03-08
CVE-2012-0587 [MEDIUM] CVE-2012-0587: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote a Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0588, and CVE-2012-0589.
nvd
CVE-2012-0586P4MEDIUMCVSS 4.3fixed in 5.12012-03-08
CVE-2012-0586 [MEDIUM] CWE-79 CVE-2012-0586: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote a Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0587, CVE-2012-0588, and CVE-2012-0589.
nvd
CVE-2013-5159P4MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5159 [MEDIUM] CWE-264 CVE-2013-5159: WebKit in Apple iOS before 7 allows remote attackers to bypass the Same Origin Policy and obtain pot WebKit in Apple iOS before 7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive information about use of the window.webkitRequestAnimationFrame API via an IFRAME element.
nvd
CVE-2011-3881P4MEDIUMCVSS 4.3fixed in 5.12011-10-25
CVE-2011-3881 [MEDIUM] CWE-79 CVE-2011-3881: WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ prope
nvd
CVE-2014-4409P4MEDIUMCVSS 4.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4409 [MEDIUM] CWE-200 CVE-2014-4409: WebKit in Apple iOS before 8 makes it easier for remote attackers to track users during private brow WebKit in Apple iOS before 8 makes it easier for remote attackers to track users during private browsing via a crafted web site that reads HTML5 application-cache data that had been stored during normal browsing.
nvd
CVE-2012-3730P4MEDIUMCVSS 4.3≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3730 [MEDIUM] CVE-2012-3730: Mail in Apple iOS before 6 does not properly handle reuse of Content-ID header values, which allows Mail in Apple iOS before 6 does not properly handle reuse of Content-ID header values, which allows remote attackers to spoof attachments via a header value that was also used in a previous e-mail message, as demonstrated by a message from a different sender.
nvd
CVE-2011-3040P4MEDIUMCVSS 4.3fixed in 6.02012-03-05
CVE-2011-3040 [MEDIUM] CWE-125 CVE-2011-3040: Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cau Google Chrome before 17.0.963.65 does not properly handle text, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2011-3434P4MEDIUMCVSS 4.3v3.0v3.1+17 more2011-10-14
CVE-2011-3434 [MEDIUM] CWE-255 CVE-2011-3434: The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
nvd
CVE-2015-7050P4MEDIUMCVSS 4.3≤ 9.12015-12-11
CVE-2015-7050 [MEDIUM] CWE-200 CVE-2015-7050: WebKit in Apple iOS before 9.2 and Safari before 9.0.2 misparses content extensions, which allows re WebKit in Apple iOS before 9.2 and Safari before 9.0.2 misparses content extensions, which allows remote attackers to obtain sensitive browsing-history information via a crafted web site.
nvd
CVE-2015-3725P4MEDIUMCVSS 4.3≤ 8.32015-07-03
CVE-2015-3725 [MEDIUM] CWE-399 CVE-2015-3725: MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.
nvd
Apple iOS vulnerabilities | cvebase