cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 194 of 207
CVE-2016-4747P4LOWCVSS 3.7≤ 9.3.52016-09-18
CVE-2016-4747 [LOW] CWE-200 CVE-2016-4747: Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle att Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.
nvd
CVE-2014-1353P4LOWCVSS 3.6≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1353 [LOW] CWE-264 CVE-2014-1353: Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vectors.
nvd
CVE-2012-3750P4LOWCVSS 3.6≤ 6.0v1.0.0+39 more2012-11-03
CVE-2012-3750 [LOW] CWE-264 CVE-2012-3750: The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.
nvd
CVE-2008-4228P4LOWCVSS 3.6v1.0v1.0.1+11 more2008-11-25
CVE-2008-4228 [LOW] CWE-264 CVE-2008-4228: The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 throug The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows physically proximate attackers to leverage the emergency-call ability of locked devices to make a phone call to an arbitrary number.
nvd
CVE-2015-3778P4LOWCVSS 3.3≤ 8.42015-08-16
CVE-2015-3778 [LOW] CWE-200 CVE-2015-3778: bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentiall bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain potentially sensitive information about MAC addresses seen in previous Wi-Fi sessions by sniffing an 802.11 network for DNAv4 broadcast traffic.
nvd
CVE-2013-5138P4MEDIUMCVSS 4.7≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5138 [MEDIUM] CVE-2013-5138: IOCatalogue in IOKitUser in Apple iOS before 7 allows attackers to cause a denial of service (NULL p IOCatalogue in IOKitUser in Apple iOS before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted application.
nvd
CVE-2008-0034P4MEDIUMCVSS 4.6v1.0.1v1.0.2+2 more2008-01-16
CVE-2008-0034 [MEDIUM] CVE-2008-0034: Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physi Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls.
nvd
CVE-2010-1775P4LOWCVSS 1.9≤ 3.2v1.0.0+18 more2010-06-22
CVE-2010-1775 [LOW] CWE-362 CVE-2010-1775: Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving the initial boot.
nvd
CVE-2014-1351P4LOWCVSS 3.6≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1351 [LOW] CWE-264 CVE-2014-1351: Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-scre Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.
nvd
CVE-2014-4372P4LOWCVSS 3.6≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4372 [LOW] CWE-59 CVE-2014-4372: syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to ch syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.
nvd
CVE-2012-0645P4LOWCVSS 1.2fixed in 5.12012-03-08
CVE-2012-0645 [LOW] CWE-264 CVE-2012-0645: Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice comm Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows physically proximate attackers to bypass the locked state via a command that forwards an active e-mail message to an arbitrary recipient.
nvd
CVE-2014-4407P4LOWCVSS 3.3≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4407 [LOW] CWE-200 CVE-2014-4407: IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which allows attackers to obtain sensitive memory-content information via an application that makes crafted IOKit function calls.
nvd
CVE-2016-1748P4LOWCVSS 3.3fixed in 9.32016-03-24
CVE-2016-1748 [LOW] CWE-200 CVE-2016-1748: IOHIDFamily in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 al IOHIDFamily in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
nvd
CVE-2023-23543P4LOWCVSS 3.6fixed in 15.7.4≥ 16.0, < 16.42023-05-08
CVE-2023-23543 [LOW] CVE-2023-23543: The issue was addressed with additional restrictions on the observability of app states. This issue The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. A sandboxed app may be able to determine which app is currently using the camera.
nvd
CVE-2020-3894P4LOWCVSS 3.1fixed in 13.42020-04-01
CVE-2020-3894 [LOW] CWE-362 CVE-2020-3894: A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
nvd
CVE-2024-23257P4LOWCVSS 3.3fixed in 16.7.62024-03-08
CVE-2024-23257 [LOW] CWE-119 CVE-2024-23257: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, visionOS 1.1. Processing an image may result in disclosure of process memory.
nvd
CVE-2016-4670P4LOWCVSS 3.3≤ 10.0.32017-02-20
CVE-2016-4670 [LOW] CWE-255 CVE-2016-4670: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "Security" component. It allows local users to discover lengths of arbitrary passwords by reading a log.
nvd
CVE-2024-40778P4LOWCVSS 3.3fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40778 [LOW] CWE-287 CVE-2024-40778: An authentication issue was addressed with improved state management. This issue is fixed in iOS 16. An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Photos in the Hidden Photos Album may be viewed without authentication.
nvd
CVE-2025-43531P4LOWCVSS 3.1fixed in 18.7.3≥ 26.0, < 26.22025-12-17
CVE-2025-43531 [LOW] CWE-362 CVE-2025-43531: A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-20671P4LOWCVSS 3.1fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20671 [LOW] CWE-77 CVE-2026-20671: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to intercept network traffic.
nvd
Apple iOS vulnerabilities | cvebase