cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 187 of 207
CVE-2020-27902P4MEDIUMCVSS 4.6fixed in 14.22020-12-08
CVE-2020-27902 [MEDIUM] CWE-306 CVE-2020-27902: An authentication issue was addressed with improved state management. This issue is fixed in iOS 14. An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.
nvd
CVE-2021-30948P4MEDIUMCVSS 4.6fixed in 15.22021-08-24
CVE-2021-30948 [MEDIUM] CWE-522 CVE-2021-30948: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.
nvd
CVE-2022-22621P4MEDIUMCVSS 4.6fixed in 15.42022-03-18
CVE-2022-22621 [MEDIUM] CVE-2022-22621: This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvd
CVE-2024-44171P4MEDIUMCVSS 4.6fixed in 17.72024-09-17
CVE-2024-44171 [MEDIUM] CVE-2024-44171: This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.
nvd
CVE-2019-8550P4MEDIUMCVSS 4.3fixed in 12.22019-12-18
CVE-2019-8550 [MEDIUM] CWE-459 CVE-2019-8550: An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the call is ringing.
nvd
CVE-2024-54470P4MEDIUMCVSS 4.6≤ 17.7.1v18.02025-01-15
CVE-2024-54470 [MEDIUM] CWE-862 CVE-2024-54470: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2024-40840P4MEDIUMCVSS 4.6fixed in 18.02024-09-17
CVE-2024-40840 [MEDIUM] CVE-2024-40840: This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2025-31227P4MEDIUMCVSS 4.6fixed in 18.52025-05-12
CVE-2025-31227 [MEDIUM] CWE-863 CVE-2025-31227: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. A A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.
nvd
CVE-2012-3746P4MEDIUMCVSS 4.3≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3746 [MEDIUM] CWE-310 CVE-2012-3746: UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which al UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which allows context-dependent attackers to obtain cleartext file content by leveraging direct access to a device's filesystem.
nvd
CVE-2015-1129P4MEDIUMCVSS 4.3≤ 8.4.12015-04-10
CVE-2015-1129 [MEDIUM] CWE-310 CVE-2015-1129: Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 cli Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.
nvd
CVE-2026-28895P4MEDIUMCVSS 4.6fixed in 26.42026-03-25
CVE-2026-28895 [MEDIUM] CWE-284 CVE-2026-28895: The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An at The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical access to an iOS device with Stolen Device Protection enabled may be able to access biometrics-gated Protected Apps with the passcode.
nvd
CVE-2025-43418P4MEDIUMCVSS 4.6fixed in 18.7.22025-11-05
CVE-2025-43418 [MEDIUM] CWE-284 CVE-2025-43418: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20661P4MEDIUMCVSS 4.6fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20661 [MEDIUM] CWE-285 CVE-2026-20661: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7 An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20645P4MEDIUMCVSS 4.6fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20645 [MEDIUM] CWE-1021 CVE-2026-20645: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2026-20674P4MEDIUMCVSS 4.6fixed in 26.32026-02-11
CVE-2026-20674 [MEDIUM] CWE-200 CVE-2026-20674: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2019-7284P4MEDIUMCVSS 4.3fixed in 12.22019-12-18
CVE-2019-7284 [MEDIUM] CVE-2019-7284: This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a malicio This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
nvd
CVE-2021-1854P4MEDIUMCVSS 4.3fixed in 14.52021-09-08
CVE-2021-1854 [MEDIUM] CWE-863 CVE-2021-1854: A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .
nvd
CVE-2023-41977P4MEDIUMCVSS 4.3fixed in 16.7.22023-10-25
CVE-2023-41977 [MEDIUM] CVE-2023-41977: The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, iOS 16.7.2 and iPadOS 16.7.2. Visiting a malicious website may reveal browsing history.
nvd
CVE-2020-3888P4MEDIUMCVSS 4.3fixed in 13.42020-04-01
CVE-2020-3888 [MEDIUM] CVE-2020-3888: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously crafted page may interfere with other web contexts.
nvd
CVE-2022-22677P4MEDIUMCVSS 4.3fixed in 15.52022-11-01
CVE-2022-22677 [MEDIUM] CVE-2022-22677: A logic issue in the handling of concurrent media was addressed with improved state handling. This i A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.
nvd
Apple iOS vulnerabilities | cvebase