Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 193 of 207
CVE-2013-5193P4MEDIUMCVSS 4.7≤ 7.0.3v7.0+2 more2013-11-18
CVE-2013-5193 [MEDIUM] CWE-255 CVE-2013-5193: The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-
The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-time password requirement, which allows local users to complete a (1) App purchase or (2) In-App purchase by leveraging previous entry of Apple ID credentials.
nvd
CVE-2018-4172P4MEDIUMCVSS 4.6fixed in 11.32018-04-03
CVE-2018-4172 [MEDIUM] CVE-2018-4172: An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Find My iPhone" component. It allows physically proximate attackers to bypass the iCloud password requirement for disabling the "Find My iPhone" feature via vectors involving a backup restore.
nvd
CVE-2015-3759P4MEDIUMCVSS 4.6≤ 8.42015-08-16
CVE-2015-3759 [MEDIUM] CWE-59 CVE-2015-3759: Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on f
Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions on filesystem modification via a symlink.
nvd
CVE-2015-1087P4LOWCVSS 2.1≤ 8.22015-04-10
CVE-2015-1087 [LOW] CWE-22 CVE-2015-1087: Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitra
Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitrary files via a crafted relative path.
nvd
CVE-2011-0195P4MEDIUMCVSS 4.3v4.3.0v4.3.12011-04-15
CVE-2011-0195 [MEDIUM] CWE-200 CVE-2011-0195: The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to
The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE: this may overlap CVE-2011-1202.
nvd
CVE-2025-43203P4MEDIUMCVSS 4.0fixed in 18.72025-09-15
CVE-2025-43203 [MEDIUM] CWE-922 CVE-2025-43203: The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS
The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical access to an unlocked device may be able to view an image in the most recently viewed locked note.
nvd
CVE-2026-28882P4MEDIUMCVSS 4.0fixed in 26.42026-03-25
CVE-2026-28882 [MEDIUM] CVE-2026-28882: This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9,
This issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2015-5869P4LOWCVSS 3.3≤ 8.4.12015-09-18
CVE-2015-5869 [LOW] CWE-20 CVE-2015-5869: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows r
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
nvd
CVE-2017-13877P4LOWCVSS 3.3fixed in 11.02018-04-03
CVE-2017-13877 [LOW] CWE-200 CVE-2017-13877: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to determine whether arbitrary files exist via a crafted app.
nvd
CVE-2013-5144P4LOWCVSS 3.3≤ 7.0.2v7.0+1 more2013-10-24
CVE-2013-5144 [LOW] CWE-264 CVE-2013-5144: Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to b
Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by tapping the emergency-call button during a certain notification and camera-pane state to trigger a NULL pointer dereference.
nvd
CVE-2014-1355P4MEDIUMCVSS 4.9≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1355 [MEDIUM] CVE-2014-1355: The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in I
The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in IOReporting in Apple OS X before 10.9.4, allows local users to cause a denial of service (NULL pointer dereference and reboot) via crafted API arguments.
nvd
CVE-2011-0158P4MEDIUMCVSS 4.3≤ 4.2v1.0.0+28 more2011-03-11
CVE-2011-0158 [MEDIUM] CWE-20 CVE-2011-0158: MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL h
MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL handlers, which allows remote attackers to cause a denial of service (persistent application crash) via crafted JavaScript code.
nvd
CVE-2013-0977P4MEDIUMCVSS 4.6≤ 6.1.2v1.0.0+44 more2013-03-20
CVE-2013-0977 [MEDIUM] CVE-2013-0977: dyld in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not properly manage the state of file
dyld in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not properly manage the state of file loading for Mach-O executable files, which allows local users to bypass intended code-signing requirements via a file that contains overlapping segments.
nvd
CVE-2020-9792P4MEDIUMCVSS 4.6fixed in 13.52020-06-09
CVE-2020-9792 [MEDIUM] CWE-20 CVE-2020-9792: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A USB device may be able to cause a denial of service.
nvd
CVE-2009-2794P4MEDIUMCVSS 4.6v2.0v2.0.0+8 more2009-09-10
CVE-2009-2794 [MEDIUM] CWE-362 CVE-2009-2794: The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod to
The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.
nvd
CVE-2021-1780P4MEDIUMCVSS 4.4fixed in 14.42021-04-02
CVE-2021-1780 [MEDIUM] CWE-665 CVE-2021-1780: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2015-1099P4MEDIUMCVSS 4.0≤ 8.22015-04-10
CVE-2015-1099 [MEDIUM] CWE-362 CVE-2015-1099: Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, App
Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app.
nvd
CVE-2025-43217P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43217 [MEDIUM] CWE-359 CVE-2025-43217: The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6,
The issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for microphone or camera access may not be correctly displayed.
nvd
CVE-2024-54550P4MEDIUMCVSS 4.0fixed in 18.22025-01-27
CVE-2024-54550 [MEDIUM] CWE-200 CVE-2024-54550: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An app may be able to view autocompleted contact information from Messages and Mail in system logs.
nvd
CVE-2016-1763P4LOWCVSS 3.5≤ 9.2.12016-03-24
CVE-2016-1763 [LOW] CWE-20 CVE-2016-1763: Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended me
Messages in Apple iOS before 9.3 does not ensure that an auto-fill action applies to the intended message thread, which allows remote authenticated users to obtain sensitive information by providing a crafted sms: URL and reading a thread.
nvd