cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 195 of 207
CVE-2015-7094P4LOWCVSS 2.6≤ 9.12015-12-11
CVE-2015-7094 [LOW] CWE-20 CVE-2015-7094: CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle atta CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL.
nvd
CVE-2012-3737P4LOWCVSS 2.1≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3737 [LOW] CWE-264 CVE-2012-3737: The Passcode Lock implementation in Apple iOS before 6 does not properly restrict photo viewing, whi The Passcode Lock implementation in Apple iOS before 6 does not properly restrict photo viewing, which allows physically proximate attackers to view arbitrary stored photos by spoofing a time value.
nvd
CVE-2013-0964P4LOWCVSS 3.6≤ 6.0.2v6.0+1 more2013-01-29
CVE-2013-0964 [LOW] CWE-20 CVE-2013-0964: The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and cop The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a length of less than one page.
nvd
CVE-2010-1810P4LOWCVSS 3.5≤ 4.0.2v1.0.0+25 more2010-09-09
CVE-2010-1810 [LOW] CVE-2010-1810: FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.
nvd
CVE-2012-3738P4LOWCVSS 3.6≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3738 [LOW] CWE-264 CVE-2012-3738: The Emergency Dialer screen in the Passcode Lock implementation in Apple iOS before 6 does not prope The Emergency Dialer screen in the Passcode Lock implementation in Apple iOS before 6 does not properly limit the dialing methods, which allows physically proximate attackers to bypass intended access restrictions and make FaceTime calls through Voice Dialing, or obtain sensitive contact information by attempting to make a FaceTime call and reading the c
nvd
CVE-2016-4665P4LOWCVSS 3.3≤ 10.0.32017-02-20
CVE-2016-4665 [LOW] CWE-200 CVE-2016-4665: An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 i An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read audio-recording metadata via a crafted app.
nvd
CVE-2016-4664P4LOWCVSS 3.3≤ 10.0.32017-02-20
CVE-2016-4664 [LOW] CWE-200 CVE-2016-4664: An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 i An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata via a crafted app.
nvd
CVE-2016-1790P4LOWCVSS 3.3≤ 9.3.12016-05-20
CVE-2016-1790 [LOW] CWE-119 CVE-2016-1790: Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
nvd
CVE-2016-4620P4LOWCVSS 3.3≤ 9.3.52016-09-18
CVE-2016-4620 [LOW] CWE-200 CVE-2016-4620: The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.
nvd
CVE-2019-8502P4LOWCVSS 3.3fixed in 12.22019-12-18
CVE-2019-8502 [LOW] CWE-20 CVE-2019-8502: An API issue existed in the handling of dictation requests. This issue was addressed with improved v An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to initiate a Dictation request without user authorization.
nvd
CVE-2019-8856P4LOWCVSS 3.3fixed in 13.32020-10-27
CVE-2019-8856 [LOW] CVE-2019-8856: An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was add An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. Calls made using Siri may be initiated using the wrong cellular
nvd
CVE-2024-23291P4LOWCVSS 3.3fixed in 17.42024-03-08
CVE-2024-23291 [LOW] CVE-2024-23291: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to accessibility notifications.
nvd
CVE-2024-23217P4LOWCVSS 3.3fixed in 17.32024-01-23
CVE-2024-23217 [LOW] CWE-922 CVE-2024-23217: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5, watchOS 10.3. An app may be able to bypass certain Privacy preferences.
nvd
CVE-2025-46279P4LOWCVSS 3.3fixed in 18.7.3≥ 26.0, < 26.22025-12-17
CVE-2025-46279 [LOW] CWE-200 CVE-2025-46279: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 an A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.
nvd
CVE-2023-40395P4LOWCVSS 3.3fixed in 16.72023-09-27
CVE-2023-40395 [LOW] CVE-2023-40395: The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 a The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access contacts.
nvd
CVE-2024-40798P4LOWCVSS 3.3fixed in 16.7.92024-07-29
CVE-2024-40798 [LOW] CWE-200 CVE-2024-40798: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to read Safari's browsing history.
nvd
CVE-2023-40427P4LOWCVSS 3.3fixed in 17.02023-09-27
CVE-2023-40427 [LOW] CVE-2023-40427: The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6, The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read sensitive location information.
nvd
CVE-2024-23289P4LOWCVSS 3.3fixed in 16.7.6≥ 17.0, < 17.42024-03-08
CVE-2024-23289 [LOW] CVE-2024-23289: A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to access private calendar information.
nvd
CVE-2022-32913P4LOWCVSS 3.3fixed in 16.02022-11-01
CVE-2022-32913 [LOW] CWE-200 CVE-2022-32913: The issue was addressed with additional restrictions on the observability of app states. This issue The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. A sandboxed app may be able to determine which app is currently using the camera.
nvd
CVE-2024-27799P4LOWCVSS 3.3fixed in 16.7.82024-06-10
CVE-2024-27799 [LOW] CVE-2024-27799: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and i This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.
nvd
Apple iOS vulnerabilities | cvebase