Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 200 of 207
CVE-2023-38605P4LOWCVSS 3.3fixed in 15.7.8≥ 16.0, < 16.62023-09-06
CVE-2023-38605 [LOW] CVE-2023-38605: This issue was addressed with improved redaction of sensitive information. This issue is fixed in ma
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.5. An app may be able to determine a user’s current location.
nvd
CVE-2023-40392P4LOWCVSS 3.3fixed in 15.7.8≥ 16.0, < 16.62023-09-06
CVE-2023-40392 [LOW] CWE-532 CVE-2023-40392: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.5. An app may be able to read sensitive location information.
nvd
CVE-2023-40394P4LOWCVSS 3.3fixed in 16.62024-01-10
CVE-2023-40394 [LOW] CWE-20 CVE-2023-40394: The issue was addressed with improved validation of environment variables. This issue is fixed in iO
The issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be able to access sensitive user data.
nvd
CVE-2024-27845P4LOWCVSS 3.3fixed in 17.52024-06-10
CVE-2024-27845 [LOW] CVE-2024-27845: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.
nvd
CVE-2024-44200P4LOWCVSS 3.3fixed in 18.12024-12-12
CVE-2024-44200 [LOW] CWE-922 CVE-2024-44200: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to read sensitive location information.
nvd
CVE-2023-42830P4LOWCVSS 3.3fixed in 16.42024-01-10
CVE-2023-42830 [LOW] CWE-359 CVE-2023-42830: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.
nvd
CVE-2023-42939P4LOWCVSS 3.3fixed in 17.12024-02-21
CVE-2023-42939 [LOW] CWE-841 CVE-2023-42939: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user's private browsing activity may be unexpectedly saved in the App Privacy Report.
nvd
CVE-2025-43442P4LOWCVSS 3.3fixed in 26.12025-11-04
CVE-2025-43442 [LOW] CWE-276 CVE-2025-43442: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 an
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to identify what other apps a user has installed.
nvd
CVE-2024-40853P4LOWCVSS 3.3fixed in 18.02024-10-28
CVE-2024-40853 [LOW] CVE-2024-40853: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to use Siri to enable Auto-Answer Calls.
nvd
CVE-2025-24090P4LOWCVSS 3.3fixed in 18.32026-01-16
CVE-2025-24090 [LOW] CWE-200 CVE-2025-24090: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-20663P4LOWCVSS 3.3fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20663 [LOW] CWE-532 CVE-2026-20663: The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, i
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps.
nvd
CVE-2013-0962P4LOWCVSS 2.6≤ 6.0.2v6.0+1 more2013-01-29
CVE-2013-0962 [LOW] CWE-79 CVE-2013-0962: Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 6.1 allows user-assisted remo
Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 6.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted content that is not properly handled during a copy-and-paste operation.
nvd
CVE-2017-13844P4LOWCVSS 2.4fixed in 11.12017-11-13
CVE-2017-13844 [LOW] CWE-200 CVE-2017-13844: An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Messages" component. It allows physically proximate attackers to view arbitrary photos via a Reply With Message action in the lock-screen state.
nvd
CVE-2015-1108P4LOWCVSS 2.1≤ 8.22015-04-10
CVE-2015-1108 [LOW] CWE-200 CVE-2015-1108: The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect p
The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.
nvd
CVE-2014-4455P4LOWCVSS 2.1≤ 8.1.22014-11-18
CVE-2014-4455 [LOW] CWE-264 CVE-2014-4455: dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segmen
dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.
nvd
CVE-2013-5153P4LOWCVSS 2.1≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5153 [LOW] CWE-264 CVE-2013-5153: Springboard in Apple iOS before 7 does not properly manage the lock state in Lost Mode, which allows
Springboard in Apple iOS before 7 does not properly manage the lock state in Lost Mode, which allows physically proximate attackers to read notifications via unspecified vectors.
nvd
CVE-2009-2796P4LOWCVSS 2.1v3.0v3.0.12009-09-10
CVE-2009-2796 [LOW] CWE-200 CVE-2009-2796: The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically pr
The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.
nvd
CVE-2009-1679P4LOWCVSS 2.1v1.0.0v1.0.1+15 more2009-06-19
CVE-2009-1679 [LOW] CWE-264 CVE-2009-1679: The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through
The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange ActiveSync with a weaker password policy, which allows physically proximate attackers to bypass the intended policy.
nvd
CVE-2015-5861P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5861 [LOW] CWE-284 CVE-2015-5861: SpringBoard in Apple iOS before 9 allows physically proximate attackers to bypass a lock-screen prev
SpringBoard in Apple iOS before 9 allows physically proximate attackers to bypass a lock-screen preview-disabled setting, and reply to an audio message, via unspecified vectors.
nvd
CVE-2015-5748P4LOWCVSS 2.1≤ 8.4.12015-08-17
CVE-2015-5748 [LOW] CWE-17 CVE-2015-5748: The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local user
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.
nvd