cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 199 of 207
CVE-2021-30804P4LOWCVSS 3.3fixed in 14.72021-09-08
CVE-2021-30804 [LOW] CVE-2021-30804: A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malic A permissions issue was addressed with improved validation. This issue is fixed in iOS 14.7. A malicious application may be able to access Find My data.
nvd
CVE-2019-8566P4LOWCVSS 3.3fixed in 12.22019-12-18
CVE-2019-8566 [LOW] CWE-20 CVE-2019-8566: An API issue existed in the handling of microphone data. This issue was addressed with improved vali An API issue existed in the handling of microphone data. This issue was addressed with improved validation. This issue is fixed in iOS 12.2. A malicious application may be able to access the microphone without indication to the user.
nvd
CVE-2017-7148P4LOWCVSS 3.3v10.3.32017-10-23
CVE-2017-7148 [LOW] CWE-200 CVE-2017-7148: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Location Framework" component. It allows attackers to obtain sensitive location information via a crafted app that reads the location variable.
nvd
CVE-2020-9773P4LOWCVSS 3.3fixed in 14.02020-04-01
CVE-2020-9773 [LOW] CVE-2020-9773: The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and i The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and iPadOS 14.0. A malicious application may be able to identify what other applications a user has installed.
nvd
CVE-2024-23228P4LOWCVSS 3.3fixed in 17.32024-04-24
CVE-2024-23228 [LOW] CWE-200 CVE-2024-23228: This issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Notes content may have been unexpectedly unlocked.
nvd
CVE-2016-7714P4LOWCVSS 3.3≤ 10.1.12017-02-20
CVE-2016-7714 [LOW] CWE-200 CVE-2016-7714: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOKit" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
nvd
CVE-2023-40384P4LOWCVSS 3.3fixed in 17.02023-09-27
CVE-2023-40384 [LOW] CVE-2023-40384: A permissions issue was addressed with improved redaction of sensitive information. This issue is fi A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read sensitive location information.
nvd
CVE-2022-22598P4LOWCVSS 3.3fixed in 15.42022-03-18
CVE-2022-22598 [LOW] CVE-2022-22598: An issue with app access to camera metadata was addressed with improved logic. This issue is fixed i An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.
nvd
CVE-2020-3844P4LOWCVSS 3.3fixed in 13.3.12020-02-27
CVE-2020-3844 [LOW] CVE-2020-3844: This issue was addressed with improved checks. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. This issue was addressed with improved checks. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Users removed from an iMessage conversation may still be able to alter state.
nvd
CVE-2020-3873P4LOWCVSS 3.3fixed in 13.3.12020-02-27
CVE-2020-3873 [LOW] CVE-2020-3873: This issue was addressed with improved setting propagation. This issue is fixed in iOS 13.3.1 and iP This issue was addressed with improved setting propagation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Turning off "Load remote content in messages” may not apply to all mail previews.
nvd
CVE-2019-8630P4LOWCVSS 3.3fixed in 12.32019-12-18
CVE-2019-8630 [LOW] CVE-2019-8630: The issue was addressed with improved UI handling. This issue is fixed in iOS 12.3. The lock screen The issue was addressed with improved UI handling. This issue is fixed in iOS 12.3. The lock screen may show a locked icon after unlocking.
nvd
CVE-2023-40434P4LOWCVSS 3.3fixed in 17.02023-09-27
CVE-2023-40434 [LOW] CVE-2023-40434: A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 17 and A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access a user's Photos Library.
nvd
CVE-2024-23256P4LOWCVSS 3.3fixed in 17.42024-03-05
CVE-2024-23256 [LOW] CVE-2024-23256: A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled.
nvd
CVE-2021-30875P4LOWCVSS 3.3fixed in 15.12021-08-24
CVE-2021-30875 [LOW] CVE-2021-30875: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1. A local attacker may be able to view contacts from the lock screen.
nvd
CVE-2024-23292P4LOWCVSS 3.3fixed in 17.42024-03-08
CVE-2024-23292 [LOW] CWE-200 CVE-2024-23292: This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 1 This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access information about a user's contacts.
nvd
CVE-2023-40439P4LOWCVSS 3.3fixed in 16.62024-01-10
CVE-2023-40439 [LOW] CWE-22 CVE-2023-40439: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to read sensitive location information.
nvd
CVE-2025-24145P4LOWCVSS 3.3fixed in 18.32025-01-27
CVE-2025-24145 [LOW] CWE-532 CVE-2025-24145: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An app may be able to view a contact's phone number in system logs.
nvd
CVE-2023-28194P4LOWCVSS 3.3fixed in 16.42023-05-08
CVE-2023-28194 [LOW] CVE-2023-28194: The issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4. An ap The issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to unexpectedly create a bookmark on the Home Screen.
nvd
CVE-2024-23242P4LOWCVSS 3.3fixed in 17.42024-03-08
CVE-2024-23242 [LOW] CWE-532 CVE-2024-23242: A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17. A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.
nvd
CVE-2024-40830P4LOWCVSS 3.3fixed in 18.02024-09-17
CVE-2024-40830 [LOW] CVE-2024-40830: This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to enumerate a user's installed apps.
nvd
Apple iOS vulnerabilities | cvebase