Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 183 of 207
CVE-2011-0161P4MEDIUMCVSS 4.3≤ 4.2v1.0.0+28 more2011-03-11
CVE-2011-0161 [MEDIUM] CWE-20 CVE-2011-0161: WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.s
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.
nvd
CVE-2015-5916P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5916 [MEDIUM] CWE-200 CVE-2015-5916: The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-tra
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.
nvd
CVE-2015-5855P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5855 [MEDIUM] CWE-200 CVE-2015-5855: Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Ce
Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Center app.
nvd
CVE-2015-3690P4MEDIUMCVSS 4.3≤ 8.32015-07-03
CVE-2015-3690 [MEDIUM] CWE-200 CVE-2015-3690: The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain
The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
nvd
CVE-2015-1125P4MEDIUMCVSS 4.3≤ 8.22015-04-10
CVE-2015-1125 [MEDIUM] CWE-17 CVE-2015-1125: The touch-events implementation in WebKit in Apple iOS before 8.3 allows remote attackers to trigger
The touch-events implementation in WebKit in Apple iOS before 8.3 allows remote attackers to trigger an association between a tap and an unintended web resource via a crafted web site.
nvd
CVE-2024-23239P4MEDIUMCVSS 4.7fixed in 17.42024-03-08
CVE-2024-23239 [MEDIUM] CWE-362 CVE-2024-23239: A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to leak sensitive user information.
nvd
CVE-2015-5904P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5904 [MEDIUM] CWE-254 CVE-2015-5904: Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web
Safari in Apple iOS before 9 allows remote attackers to spoof the relationship between URLs and web content via a crafted web site.
nvd
CVE-2017-7144P4MEDIUMCVSS 4.3≤ 10.3.32017-10-23
CVE-2017-7144 [MEDIUM] CWE-275 CVE-2017-7144: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.
nvd
CVE-2019-8769P4MEDIUMCVSS 4.3fixed in 13.12019-12-18
CVE-2019-8769 [MEDIUM] CVE-2019-8769: An issue existed in the drawing of web page elements. The issue was addressed with improved logic. T
An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.
nvd
CVE-2023-41997P4MEDIUMCVSS 4.6fixed in 16.7.2≥ 17.0, < 17.12023-10-25
CVE-2023-41997 [MEDIUM] CVE-2023-41997: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2023-41982P4MEDIUMCVSS 4.6fixed in 16.7.2≥ 17.0, < 17.12023-10-25
CVE-2023-41982 [MEDIUM] CVE-2023-41982: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2024-44274P4MEDIUMCVSS 4.6fixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44274 [MEDIUM] CVE-2024-44274: The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 1
The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2024-40818P4MEDIUMCVSS 4.6fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40818 [MEDIUM] CVE-2024-40818: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2014-4467P4MEDIUMCVSS 4.3≤ 8.1.22015-01-30
CVE-2014-4467 [MEDIUM] CWE-17 CVE-2014-4467: WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during t
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.
nvd
CVE-2014-1350P4MEDIUMCVSS 4.6≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1350 [MEDIUM] CWE-264 CVE-2014-1350: Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iClou
Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
nvd
CVE-2024-23251P4MEDIUMCVSS 4.6fixed in 16.7.8≥ 17.0, < 17.52024-06-10
CVE-2024-23251 [MEDIUM] CWE-287 CVE-2024-23251: An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. An attacker with physical access may be able to leak Mail account credentials.
nvd
CVE-2026-43811P4MEDIUMCVSS 4.7fixed in 26.62026-07-27
CVE-2026-43811 [MEDIUM] CWE-362 CVE-2026-43811: A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6
A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.
nvd
CVE-2021-1872P4MEDIUMCVSS 4.3fixed in 14.52021-09-08
CVE-2021-1872 [MEDIUM] CVE-2021-1872: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. Muting a CallKit call while ringing may not result in mute being enabled.
nvd
CVE-2020-9978P4MEDIUMCVSS 4.5fixed in 14.02021-04-02
CVE-2020-9978 [MEDIUM] CVE-2020-9978: This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.
This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An attacker in a privileged network position may be able to unexpectedly alter application state.
nvd
CVE-2025-43460P4MEDIUMCVSS 4.6fixed in 26.12025-11-04
CVE-2025-43460 [MEDIUM] CWE-200 CVE-2025-43460: A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. A
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd