Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 191 of 207
CVE-2018-4244P4MEDIUMCVSS 4.6fixed in 11.42018-06-08
CVE-2018-4244 [MEDIUM] CWE-200 CVE-2018-4244: An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri Contacts" component. It allows physically proximate attackers to discover private contact information via Siri.
nvd
CVE-2017-2452P4MEDIUMCVSS 4.6≤ 10.2.12017-04-02
CVE-2017-2452 [MEDIUM] CWE-200 CVE-2017-2452: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to read text messages on the lock screen via unspecified vectors.
nvd
CVE-2014-4353P4MEDIUMCVSS 4.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4353 [MEDIUM] CWE-362 CVE-2014-4353: Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by
Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.
nvd
CVE-2018-4388P4MEDIUMCVSS 4.6fixed in 12.12019-04-03
CVE-2018-4388 [MEDIUM] CWE-200 CVE-2018-4388: A lock screen issue allowed access to the share function on a locked device. This issue was addresse
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.1.
nvd
CVE-2021-30932P4MEDIUMCVSS 4.6fixed in 15.22021-08-24
CVE-2021-30932 [MEDIUM] CVE-2021-30932: The issue was addressed with improved permissions logic. This issue is fixed in iOS 15.2 and iPadOS
The issue was addressed with improved permissions logic. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
CVE-2022-22622P4MEDIUMCVSS 4.6fixed in 15.42022-03-18
CVE-2022-22622 [MEDIUM] CVE-2022-22622: This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A pe
This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvd
CVE-2021-30699P4MEDIUMCVSS 4.6fixed in 14.62021-09-08
CVE-2021-30699 [MEDIUM] CVE-2021-30699: A window management issue was addressed with improved state management. This issue is fixed in iOS 1
A window management issue was addressed with improved state management. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be able to view restricted content from the lockscreen.
nvd
CVE-2023-42855P4MEDIUMCVSS 4.6fixed in 17.12024-02-21
CVE-2023-42855 [MEDIUM] CVE-2023-42855: This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS
This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to silently persist an Apple ID on an erased device.
nvd
CVE-2017-2399P4MEDIUMCVSS 4.6≤ 10.2.12017-04-02
CVE-2017-2399 [MEDIUM] CWE-326 CVE-2017-2399: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Pasteboard" component. It allows physically proximate attackers to read the pasteboard by leveraging the use of an encryption key derived only from the hardware UID (rather than that UID in addition to the user passcode).
nvd
CVE-2015-1115P4MEDIUMCVSS 4.4≤ 8.22015-04-10
CVE-2015-1115 [MEDIUM] CWE-284 CVE-2015-1115: The Telephony component in Apple iOS before 8.3 allows attackers to bypass a sandbox protection mech
The Telephony component in Apple iOS before 8.3 allows attackers to bypass a sandbox protection mechanism and access unintended telephone capabilities via a crafted app.
nvd
CVE-2015-5824P4MEDIUMCVSS 4.3≤ 8.4.12015-09-18
CVE-2015-5824 [MEDIUM] CWE-310 CVE-2015-5824: The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly veri
The NSURL implementation in the CFNetwork SSL component in Apple iOS before 9 does not properly verify X.509 certificates from SSL servers after a certificate change, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2022-32945P4MEDIUMCVSS 4.3fixed in 16.12022-12-15
CVE-2022-32945 [MEDIUM] CWE-284 CVE-2022-32945: An access issue was addressed with additional sandbox restrictions on third-party apps. This issue i
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.
nvd
CVE-2023-42934P4MEDIUMCVSS 4.2fixed in 17.02024-01-10
CVE-2023-42934 [MEDIUM] CWE-200 CVE-2023-42934: An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed i
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app with root privileges may be able to access private information.
nvd
CVE-2025-43230P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43230 [MEDIUM] CWE-863 CVE-2025-43230: The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPad
The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to access user-sensitive data.
nvd
CVE-2008-4233P4LOWCVSS 2.6v1.0v1.0.1+11 more2008-11-25
CVE-2008-4233 [LOW] CVE-2008-4233: Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isol
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.
nvd
CVE-2010-4008P4MEDIUMCVSS 4.3fixed in 4.22010-11-17
CVE-2010-4008 [MEDIUM] CWE-119 CVE-2010-4008: libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, an
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2007-2400P4MEDIUMCVSS 4.3≤ 1.02007-06-25
CVE-2007-2400 [MEDIUM] CWE-79 CVE-2007-2400: Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhon
Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.
nvd
CVE-2012-2870P4MEDIUMCVSS 4.3≤ 6.1.4v1.0.0+46 more2012-08-31
CVE-2012-2870 [MEDIUM] CWE-399 CVE-2012-2870: libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage m
libxslt 1.1.26 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly manage memory, which might allow remote attackers to cause a denial of service (application crash) via a crafted XSLT expression that is not properly identified during XPath navigation, related to (1) the xsltCompileLocationPathPattern function in libxslt/patte
nvd
CVE-2013-5142P4MEDIUMCVSS 4.9≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5142 [MEDIUM] CWE-200 CVE-2013-5142: The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allow
The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obtain sensitive information from kernel stack memory via the (1) msgctl API or (2) segctl API.
nvd
CVE-2011-3027P4MEDIUMCVSS 4.3fixed in 6.02012-02-16
CVE-2011-3027 [MEDIUM] CWE-704 CVE-2011-3027: Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during
Google Chrome before 17.0.963.56 does not properly perform a cast of an unspecified variable during handling of columns, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd