cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 201 of 207
CVE-2015-5923P4LOWCVSS 2.1≤ 9.0.12015-10-09
CVE-2015-5923 [LOW] CWE-200 CVE-2015-5923: Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which al Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.
nvd
CVE-2015-1107P4LOWCVSS 1.9≤ 8.22015-04-10
CVE-2015-1107 [LOW] CVE-2015-1107: The Lock Screen component in Apple iOS before 8.3 does not properly implement the erasure feature fo The Lock Screen component in Apple iOS before 8.3 does not properly implement the erasure feature for incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.
nvd
CVE-2015-1114P4LOWCVSS 1.9≤ 8.22015-04-10
CVE-2015-1114 [LOW] CWE-200 CVE-2015-1114: The Sandbox Profiles component in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to d The Sandbox Profiles component in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to discover hardware identifiers via a crafted app.
nvd
CVE-2015-1096P4LOWCVSS 1.9≤ 8.22015-04-10
CVE-2015-1096 [LOW] CWE-200 CVE-2015-1096: IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attac IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.
nvd
CVE-2013-0979P4LOWCVSS 1.9≤ 6.1.2v1.0.0+44 more2013-03-20
CVE-2013-0979 [LOW] CWE-264 CVE-2013-0979: lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the per lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the permission-setting step of a backup restoration, which allows local users to change the permissions of arbitrary files via a backup that contains a pathname with a symlink.
nvd
CVE-2014-4386P4LOWCVSS 1.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4386 [LOW] CWE-362 CVE-2014-4386: Race condition in the App Installation feature in Apple iOS before 8 allows local users to gain priv Race condition in the App Installation feature in Apple iOS before 8 allows local users to gain privileges and install unverified apps by leveraging /tmp write access.
nvd
CVE-2018-4446P4LOWCVSS 3.3fixed in 12.1.12019-04-03
CVE-2018-4446 [LOW] CWE-20 CVE-2018-4446: This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1. This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1.
nvd
CVE-2016-1849P4LOWCVSS 3.3≤ 9.3.12016-05-20
CVE-2016-1849 [LOW] CWE-200 CVE-2016-1849: The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3 The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.
nvd
CVE-2016-4749P4LOWCVSS 3.3≤ 9.3.52016-09-18
CVE-2016-4749 [LOW] CWE-200 CVE-2016-4749: Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.
nvd
CVE-2018-4322P4LOWCVSS 3.3fixed in 12.02019-04-03
CVE-2018-4322 [LOW] CWE-20 CVE-2018-4322: This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12. This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.
nvd
CVE-2022-32835P4LOWCVSS 3.3fixed in 16.02022-11-01
CVE-2022-32835 [LOW] CWE-200 CVE-2022-32835: This issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An ap This issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An app may be able to read a persistent device identifier.
nvd
CVE-2023-23541P4LOWCVSS 3.3fixed in 15.7.4≥ 16.0, < 16.42023-05-08
CVE-2023-23541 [LOW] CWE-922 CVE-2023-23541: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to access information about a user’s contacts.
nvd
CVE-2015-5907P4LOWCVSS 2.6≤ 8.4.12015-09-18
CVE-2015-5907 [LOW] CWE-310 CVE-2015-5907: WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by le WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.
nvd
CVE-2024-54558P4LOWCVSS 2.8fixed in 18.02025-03-10
CVE-2024-54558 [LOW] CWE-451 CVE-2024-54558: A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed i A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.
nvd
CVE-2024-23255P4LOWCVSS 2.4fixed in 17.42024-03-08
CVE-2024-23255 [LOW] CWE-287 CVE-2024-23255: An authentication issue was addressed with improved state management. This issue is fixed in iOS 17. An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.
nvd
CVE-2023-32365P4LOWCVSS 2.4fixed in 15.7.6≥ 16.0, < 16.52023-06-23
CVE-2023-32365 [LOW] CVE-2023-32365: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, i The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, iOS 16.5 and iPadOS 16.5. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
nvd
CVE-2024-44123P4LOWCVSS 2.3fixed in 18.02024-10-28
CVE-2024-44123 [LOW] CVE-2024-44123: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iP A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with root privileges may be able to access keyboard input and location information without user consent.
nvd
CVE-2015-1106P4LOWCVSS 2.1≤ 8.22015-04-10
CVE-2015-1106 [LOW] CWE-200 CVE-2015-1106: The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.
nvd
CVE-2015-5850P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5850 [LOW] CWE-254 CVE-2015-5850: AppleKeyStore in Apple iOS before 9 allows physically proximate attackers to reset the count of inco AppleKeyStore in Apple iOS before 9 allows physically proximate attackers to reset the count of incorrect passcode attempts via a device backup.
nvd
CVE-2013-5162P4LOWCVSS 2.1≤ 7.0.2v7.0+1 more2013-10-24
CVE-2013-5162 [LOW] CWE-264 CVE-2013-5162: Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to b Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass the passcode-failure disabled state by leveraging certain incorrect visibility of the passcode-entry view after use of the Phone app.
nvd
Apple iOS vulnerabilities | cvebase