Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 189 of 207
CVE-2011-1107P4MEDIUMCVSS 4.3fixed in 5.02011-03-01
CVE-2011-1107 [MEDIUM] CVE-2011-1107: Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the U
Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.
nvd
CVE-2015-7022P4MEDIUMCVSS 4.3≤ 9.0.22015-10-23
CVE-2015-7022 [MEDIUM] CWE-200 CVE-2015-7022: The Telephony subsystem in Apple iOS before 9.1 allows attackers to obtain sensitive call-status inf
The Telephony subsystem in Apple iOS before 9.1 allows attackers to obtain sensitive call-status information via a crafted app.
nvd
CVE-2012-2889P4MEDIUMCVSS 4.3≤ 6.0.2v6.0+1 more2012-09-26
CVE-2012-2889 [MEDIUM] CWE-79 CVE-2012-2889: Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attacker
Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."
nvd
CVE-2016-1780P4MEDIUMCVSS 4.3≤ 9.2.12016-03-24
CVE-2016-1780 [MEDIUM] CWE-200 CVE-2016-1780: WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion
WebKit in Apple iOS before 9.3 does not prevent hidden web views from reading orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment via a crafted web site.
nvd
CVE-2016-4603P4MEDIUMCVSS 4.3≤ 9.3.22016-07-22
CVE-2016-4603 [MEDIUM] CWE-254 CVE-2016-4603: Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mecha
Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.
nvd
CVE-2011-2845P4MEDIUMCVSS 4.3fixed in 6.02011-10-25
CVE-2011-2845 [MEDIUM] CWE-20 CVE-2011-2845: Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
nvd
CVE-2018-4168P4MEDIUMCVSS 4.6fixed in 11.32018-04-03
CVE-2018-4168 [MEDIUM] CWE-200 CVE-2018-4168: An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Files Widget" component. It allows physically proximate attackers to obtain sensitive information by leveraging the display of cached data on a locked device.
nvd
CVE-2026-43743P4MEDIUMCVSS 4.7fixed in 26.5.22026-06-29
CVE-2026-43743 [MEDIUM] CWE-362 CVE-2026-43743: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and i
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2022-32935P4MEDIUMCVSS 4.6fixed in 15.7.12022-11-01
CVE-2022-32935 [MEDIUM] CWE-287 CVE-2022-32935: A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.
nvd
CVE-2016-7634P4MEDIUMCVSS 4.6≤ 10.1.12017-02-20
CVE-2016-7634 [MEDIUM] CWE-200 CVE-2016-7634: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Accessibility" component, which accepts spoken passwords without considering that they are locally audible.
nvd
CVE-2018-4252P4MEDIUMCVSS 4.6fixed in 11.42018-06-08
CVE-2018-4252 [MEDIUM] CWE-200 CVE-2018-4252: An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to bypass the lock-screen protection mechanism and obtain private notification content via Siri.
nvd
CVE-2023-32391P4MEDIUMCVSS 4.6fixed in 15.7.6≥ 16.0, < 16.52023-06-23
CVE-2023-32391 [MEDIUM] CWE-125 CVE-2023-32391: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, w
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. A shortcut may be able to use sensitive data with certain actions without prompting the user.
nvd
CVE-2024-44235P4MEDIUMCVSS 4.6fixed in 18.12024-10-28
CVE-2024-44235 [MEDIUM] CWE-754 CVE-2024-44235: The issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An at
The issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.
nvd
CVE-2022-22671P4MEDIUMCVSS 4.6fixed in 15.42022-03-18
CVE-2022-22671 [MEDIUM] CVE-2022-22671: An authentication issue was addressed with improved state management. This issue is fixed in iOS 15.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to access photos from the lock screen.
nvd
CVE-2025-43452P4MEDIUMCVSS 4.6fixed in 26.12025-11-04
CVE-2025-43452 [MEDIUM] CWE-359 CVE-2025-43452: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggestions may display sensitive information on the lock screen.
nvd
CVE-2025-43422P4MEDIUMCVSS 4.6fixed in 26.12025-11-04
CVE-2025-43422 [MEDIUM] CWE-288 CVE-2025-43422: The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1.
The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a device may be able to disable Stolen Device Protection.
nvd
CVE-2019-6222P4MEDIUMCVSS 4.3fixed in 12.22019-12-18
CVE-2019-6222 [MEDIUM] CVE-2019-6222: A consistency issue was addressed with improved state handling. This issue is fixed in iOS 12.2. A w
A consistency issue was addressed with improved state handling. This issue is fixed in iOS 12.2. A website may be able to access the microphone without the microphone use indicator being shown.
nvd
CVE-2015-6997P4MEDIUMCVSS 4.3≤ 9.0.22015-10-23
CVE-2015-6997 [MEDIUM] CWE-254 CVE-2015-6997: The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecR
The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.
nvd
CVE-2019-8727P4MEDIUMCVSS 4.3fixed in 13.02019-12-18
CVE-2019-8727 [MEDIUM] CVE-2019-8727: A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting
A logic issue was addressed with improved state management. This issue is fixed in iOS 13. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2016-7581P4MEDIUMCVSS 4.3≤ 10.0.32017-02-20
CVE-2016-7581 [MEDIUM] CWE-20 CVE-2016-7581: An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "Safari" component, which allows remote web servers to cause a denial of service via a crafted URL.
nvd