cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 184 of 207
CVE-2017-7152P4MEDIUMCVSS 4.3fixed in 11.22017-12-27
CVE-2017-7152 [MEDIUM] CVE-2017-7152: An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "Mail Message Framework" component. It allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2026-28963P4MEDIUMCVSS 4.6fixed in 26.52026-05-11
CVE-2026-28963 [MEDIUM] CWE-359 CVE-2026-28963: A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and i A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensitive user data during iPhone Mirroring.
nvd
CVE-2026-20640P4MEDIUMCVSS 4.6fixed in 26.32026-02-11
CVE-2026-20640 [MEDIUM] CWE-703 CVE-2026-20640: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone during iPhone Mirroring with Mac.
nvd
CVE-2022-32868P4MEDIUMCVSS 4.3fixed in 15.72022-09-20
CVE-2022-32868 [MEDIUM] CVE-2022-32868: A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16 A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.
nvd
CVE-2022-26731P4MEDIUMCVSS 4.3fixed in 15.52022-05-26
CVE-2022-26731 [MEDIUM] CVE-2022-26731: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious website may be able to track users in Safari private browsing mode.
nvd
CVE-2023-42843P4MEDIUMCVSS 4.3fixed in 16.7.2≥ 17.0, < 17.12024-02-21
CVE-2023-42843 [MEDIUM] CWE-290 CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2025-43228P4MEDIUMCVSS 4.3fixed in 18.62025-07-30
CVE-2025-43228 [MEDIUM] CWE-451 CVE-2025-43228: The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18 The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2021-30943P4MEDIUMCVSS 4.3fixed in 15.22021-08-24
CVE-2021-30943 [MEDIUM] CWE-613 CVE-2021-30943: An issue in the handling of group membership was resolved with improved logic. This issue is fixed i An issue in the handling of group membership was resolved with improved logic. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1. A malicious user may be able to leave a messages group but continue to receive messages in that group.
nvd
CVE-2025-30425P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30425 [MEDIUM] CWE-284 CVE-2025-30425: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
nvd
CVE-2024-23273P4MEDIUMCVSS 4.3fixed in 17.42024-03-08
CVE-2024-23273 [MEDIUM] CWE-295 CVE-2024-23273: This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.
nvd
CVE-2023-35984P4MEDIUMCVSS 4.3fixed in 17.02023-09-27
CVE-2023-35984 [MEDIUM] CWE-787 CVE-2023-35984: The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An attacker in physical proximity can cause a limited out of bounds write.
nvd
CVE-2025-30467P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30467 [MEDIUM] CWE-451 CVE-2025-30467: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2025-43392P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43392 [MEDIUM] CWE-942 CVE-2025-43392: The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18 The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A website may exfiltrate image data cross-origin.
nvd
CVE-2023-42952P4MEDIUMCVSS 4.4fixed in 17.12024-02-21
CVE-2023-42952 [MEDIUM] CWE-269 CVE-2023-42952: The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.
nvd
CVE-2025-43493P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43493 [MEDIUM] CWE-290 CVE-2025-43493: The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPa The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2023-28208P4MEDIUMCVSS 4.3fixed in 16.32023-09-06
CVE-2023-28208 [MEDIUM] CVE-2023-28208: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may send a text from a secondary eSIM despite configuring a contact to use a primary eSIM.
nvd
CVE-2026-28971P4MEDIUMCVSS 4.3fixed in 26.52026-05-11
CVE-2026-28971 [MEDIUM] CWE-1021 CVE-2026-28971: The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
nvd
CVE-2026-39869P4MEDIUMCVSS 4.3fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-39869 [MEDIUM] CWE-120 CVE-2026-39869: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file may terminate the process.
nvd
CVE-2026-20691P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-20691 [MEDIUM] CWE-497 CVE-2026-20691: An authorization issue was addressed with improved state management. This issue is fixed in Safari 2 An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2025-46299P4MEDIUMCVSS 4.3fixed in 26.22026-01-09
CVE-2025-46299 [MEDIUM] CWE-284 CVE-2025-46299: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Sa A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
nvd
Apple iOS vulnerabilities | cvebase