Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 198 of 207
CVE-2024-44290P4LOWCVSS 3.3fixed in 18.12024-12-12
CVE-2024-44290 [LOW] CVE-2024-44290: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, watchOS 11.1. An app may be able to determine a user’s current location.
nvd
CVE-2023-42949P4LOWCVSS 3.3fixed in 17.02024-07-29
CVE-2023-42949 [LOW] CVE-2023-42949: This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17,
This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to access edited photos saved to a temporary directory.
nvd
CVE-2025-46277P4LOWCVSS 3.3fixed in 26.22025-12-17
CVE-2025-46277 [LOW] CWE-532 CVE-2025-46277: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPad
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, watchOS 26.2. An app may be able to access a user’s Safari history.
nvd
CVE-2022-42839P4LOWCVSS 3.3fixed in 16.22024-01-10
CVE-2022-42839 [LOW] CWE-200 CVE-2022-42839: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to read sensitive location information.
nvd
CVE-2023-42925P4LOWCVSS 3.3fixed in 17.02024-07-29
CVE-2023-42925 [LOW] CWE-200 CVE-2023-42925: The issue was addressed with improved restriction of data container access. This issue is fixed in i
The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access Notes attachments.
nvd
CVE-2023-42957P4LOWCVSS 3.3fixed in 17.02024-07-29
CVE-2023-42957 [LOW] CWE-284 CVE-2023-42957: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iP
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app may be able to read sensitive location information.
nvd
CVE-2026-28957P4LOWCVSS 3.3fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28957 [LOW] CWE-284 CVE-2026-28957: An issue with app access to camera metadata was addressed with improved logic. This issue is fixed i
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to capture a user's screen.
nvd
CVE-2025-43437P4LOWCVSS 3.3fixed in 26.12025-12-12
CVE-2025-43437 [LOW] CWE-200 CVE-2025-43437: An information disclosure issue was addressed with improved privacy controls. This issue is fixed in
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 26.1 and iPadOS 26.1. An app may be able to fingerprint the user.
nvd
CVE-2026-20656P4LOWCVSS 3.3fixed in 18.7.52026-02-11
CVE-2026-20656 [LOW] CWE-285 CVE-2026-20656: A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5
A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. An app may be able to access a user's Safari history.
nvd
CVE-2011-3427P4LOWCVSS 2.6v3.0v3.1+17 more2011-10-14
CVE-2011-3427 [LOW] CWE-200 CVE-2011-3427: The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.
nvd
CVE-2025-43365P4LOWCVSS 2.8fixed in 26.02025-11-04
CVE-2025-43365 [LOW] CWE-20 CVE-2025-43365: A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 1
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26 and iPadOS 26. An unprivileged process may be able to terminate a root processes.
nvd
CVE-2016-4593P4LOWCVSS 2.4≤ 9.3.22016-07-22
CVE-2016-4593 [LOW] CWE-200 CVE-2016-4593: The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read
The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.
nvd
CVE-2014-1360P4LOWCVSS 2.1≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1360 [LOW] CWE-20 CVE-2014-1360: Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which make
Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors.
nvd
CVE-2013-0963P4LOWCVSS 2.1≤ 6.0.2v6.0+1 more2013-01-29
CVE-2013-0963 [LOW] CWE-20 CVE-2013-0963: Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID ce
Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.
nvd
CVE-2014-4371P4LOWCVSS 1.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4371 [LOW] CWE-665 CVE-2014-4371: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4419, CVE-2014-4420, and CVE-2014-4421.
nvd
CVE-2014-4419P4LOWCVSS 1.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4419 [LOW] CVE-2014-4419: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4420, and CVE-2014-4421.
nvd
CVE-2014-4420P4LOWCVSS 1.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4420 [LOW] CVE-2014-4420: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4421.
nvd
CVE-2014-4421P4LOWCVSS 1.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4421 [LOW] CVE-2014-4421: The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4420.
nvd
CVE-2015-1085P4LOWCVSS 1.9≤ 8.22015-04-10
CVE-2015-1085 [LOW] CWE-264 CVE-2015-1085: AppleKeyStore in Apple iOS before 8.3 does not properly restrict a certain passcode-confirmation int
AppleKeyStore in Apple iOS before 8.3 does not properly restrict a certain passcode-confirmation interface, which makes it easier for attackers to verify correct passcode guesses via a crafted app.
nvd
CVE-2012-3725P4LOWCVSS 3.3≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3725 [LOW] CWE-200 CVE-2012-3725: The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets co
The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC address of a host on a previously used network, which might allow remote attackers to obtain sensitive information about previous device locations by sniffing an unencrypted Wi-Fi network for these packets.
nvd