cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 192 of 207
CVE-2011-2800P4MEDIUMCVSS 4.3fixed in 5.02011-08-03
CVE-2011-2800 [MEDIUM] CWE-200 CVE-2011-2800: Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive informatio Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.
nvd
CVE-2016-7638P4MEDIUMCVSS 4.6≤ 10.1.12017-02-20
CVE-2016-7638 [MEDIUM] CWE-254 CVE-2016-7638: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Find My iPhone" component, which allows physically proximate attackers to disable this component by bypassing authentication.
nvd
CVE-2015-7062P4MEDIUMCVSS 4.6≤ 9.12015-12-11
CVE-2015-7062 [MEDIUM] CWE-264 CVE-2015-7062: Apple OS X before 10.11.2 and tvOS before 9.1 allow local users to bypass intended configuration-pro Apple OS X before 10.11.2 and tvOS before 9.1 allow local users to bypass intended configuration-profile installation restrictions via unspecified vectors.
nvd
CVE-2016-7597P4MEDIUMCVSS 4.6≤ 10.1.12017-02-20
CVE-2016-7597 [MEDIUM] CWE-254 CVE-2016-7597: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to maintain the unlocked state via vectors related to Handoff with Siri.
nvd
CVE-2021-1835P4MEDIUMCVSS 4.6fixed in 14.52021-09-08
CVE-2021-1835 [MEDIUM] CWE-862 CVE-2021-1835: This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A pe This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.
nvd
CVE-2012-3736P4MEDIUMCVSS 4.6≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3736 [MEDIUM] CWE-264 CVE-2012-3736: The Passcode Lock implementation in Apple iOS before 6 allows physically proximate attackers to bypa The Passcode Lock implementation in Apple iOS before 6 allows physically proximate attackers to bypass an intended passcode requirement via vectors related to ending a FaceTime call.
nvd
CVE-2010-3828P4MEDIUMCVSS 4.3≤ 4.1v1.0.0+27 more2010-11-26
CVE-2010-3828 [MEDIUM] CVE-2010-3828: iAd Content Display in Apple iOS before 4.2 allows man-in-the-middle attackers to make calls via a c iAd Content Display in Apple iOS before 4.2 allows man-in-the-middle attackers to make calls via a crafted URL in an ad.
nvd
CVE-2026-20605P4MEDIUMCVSS 4.6fixed in 18.7.52026-02-11
CVE-2026-20605 [MEDIUM] CWE-119 CVE-2026-20605: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to crash a system process.
nvd
CVE-2009-0958P4MEDIUMCVSS 4.3v1.0.0v1.0.1+15 more2009-06-19
CVE-2009-0958 [MEDIUM] CWE-200 CVE-2009-0958: Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows remote Exchange servers to obtain sensitive information such as credentials.
nvd
CVE-2019-8906P4MEDIUMCVSS 4.4fixed in 12.22019-02-18
CVE-2019-8906 [MEDIUM] CWE-125 CVE-2019-8906: do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is mis do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
nvd
CVE-2013-5161P4MEDIUMCVSS 4.4≤ 7.0.1v7.02013-09-28
CVE-2013-5161 [MEDIUM] CWE-264 CVE-2013-5161: Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physic Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement, and open the Camera app or read the list of all recently opened apps, by leveraging unspecified transition errors.
nvd
CVE-2016-7759P4MEDIUMCVSS 4.3≤ 9.3.52017-02-20
CVE-2016-7759 [MEDIUM] CWE-200 CVE-2016-7759: An issue was discovered in certain Apple products. iOS before 10 is affected. The issue involves the An issue was discovered in certain Apple products. iOS before 10 is affected. The issue involves the "Springboard" component, which allows physically proximate attackers to obtain sensitive information by viewing application snapshots in the Task Switcher.
nvd
CVE-2016-7577P4LOWCVSS 3.7≤ 10.0.32017-02-20
CVE-2016-7577 [LOW] CWE-200 CVE-2016-7577: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "FaceTime" component, which allows remote attackers to trigger memory corruption and obtain audio data from a call that appeared to have ended.
nvd
CVE-2023-42973P4MEDIUMCVSS 4.0v17.02025-04-11
CVE-2023-42973 [MEDIUM] CWE-285 CVE-2023-42973: Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPad Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.
nvd
CVE-2008-4229P4LOWCVSS 3.7v1.0v1.0.1+11 more2008-11-25
CVE-2008-4229 [LOW] CWE-362 CVE-2008-4229: Race condition in the Passcode Lock feature in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPo Race condition in the Passcode Lock feature in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.0 through 2.1 allows physically proximate attackers to remove the lock and launch arbitrary applications by restoring the device from a backup.
nvd
CVE-2017-13852P4LOWCVSS 3.3fixed in 11.12017-11-13
CVE-2017-13852 [LOW] CWE-200 CVE-2017-13852: An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbitrary apps via a crafted app that accesses process information at a high rate.
nvd
CVE-2013-5160P4LOWCVSS 3.3≤ 7.0.1v7.02013-09-28
CVE-2013-5160 [LOW] CWE-264 CVE-2013-5160: Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to b Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of taps of the emergency-call button to trigger a NULL pointer dereference.
nvd
CVE-2015-7046P4LOWCVSS 2.6≤ 9.12015-12-11
CVE-2015-7046 [LOW] CWE-200 CVE-2015-7046: The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchO The Sandbox feature in xnu in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not properly implement privilege separation, which allows attackers to bypass the ASLR protection mechanism via a crafted app with root privileges.
nvd
CVE-2013-3953P4MEDIUMCVSS 4.9≤ 6.1.4v1.0.0+46 more2013-06-05
CVE-2013-3953 [MEDIUM] CWE-200 CVE-2013-3953: The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8 The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8.x does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted call.
nvd
CVE-2014-1320P4MEDIUMCVSS 4.9≤ 7.1v7.0+6 more2014-04-23
CVE-2014-1320 [MEDIUM] CWE-200 CVE-2014-1320: IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.
nvd
Apple iOS vulnerabilities | cvebase