Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 202 of 207
CVE-2014-4463P4LOWCVSS 2.1≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4463 [LOW] CWE-264 CVE-2014-4463: Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection me
Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or transmit a Photo Library photo, via the FaceTime "Leave a Message" feature.
nvd
CVE-2015-1113P4LOWCVSS 1.9≤ 8.22015-04-10
CVE-2015-1113 [LOW] CWE-200 CVE-2015-1113: The Sandbox Profiles component in Apple iOS before 8.3 allows attackers to read the (1) telephone nu
The Sandbox Profiles component in Apple iOS before 8.3 allows attackers to read the (1) telephone number or (2) e-mail address of a recent contact via a crafted app.
nvd
CVE-2014-1352P4LOWCVSS 1.9≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1352 [LOW] CWE-264 CVE-2014-1352: Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempt
Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.
nvd
CVE-2011-3440P4LOWCVSS 1.2≤ 5.0v1.0+40 more2011-11-11
CVE-2011-3440 [LOW] CWE-264 CVE-2011-3440: The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the lo
The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.
nvd
CVE-2018-4352P4LOWCVSS 3.3fixed in 12.02019-04-03
CVE-2018-4352 [LOW] CWE-200 CVE-2018-4352: A consistency issue existed in the handling of application snapshots. The issue was addressed with i
A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of notes deletions. This issue affected versions prior to iOS 12.
nvd
CVE-2020-9780P4LOWCVSS 3.3fixed in 13.42020-04-01
CVE-2020-9780 [LOW] CWE-212 CVE-2020-9780: The issue was resolved by clearing application previews when content is deleted. This issue is fixed
The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.
nvd
CVE-2024-40822P4LOWCVSS 2.4fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40822 [LOW] CWE-284 CVE-2024-40822: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen.
nvd
CVE-2023-32390P4LOWCVSS 2.4fixed in 16.52023-06-23
CVE-2023-32390 [LOW] CWE-125 CVE-2023-32390: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup.
nvd
CVE-2024-23240P4LOWCVSS 2.4fixed in 17.42024-03-08
CVE-2024-23240 [LOW] CVE-2024-23240: The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4. Shake
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
nvd
CVE-2014-4460P4LOWCVSS 2.1≤ 8.1v8.0+2 more2014-11-18
CVE-2014-4460 [LOW] CWE-200 CVE-2014-4460: CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cac
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.
nvd
CVE-2009-1680P4LOWCVSS 2.1v1.0.0v1.0.1+15 more2009-06-19
CVE-2009-1680 [LOW] CWE-200 CVE-2009-1680: Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not
Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows physically proximate attackers to obtain the search history.
nvd
CVE-2015-5832P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5832 [LOW] CWE-200 CVE-2015-5832: The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from t
The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from the keychain upon a signout action, which might allow physically proximate attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2015-5892P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5892 [LOW] CWE-200 CVE-2015-5892: Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side p
Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.
nvd
CVE-2015-7080P4LOWCVSS 2.1≤ 9.12015-12-11
CVE-2015-7080 [LOW] CWE-200 CVE-2015-7080: Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side
Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.
nvd
CVE-2013-5158P4LOWCVSS 2.1≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5158 [LOW] CWE-264 CVE-2013-5158: The Social subsystem in Apple iOS before 7 does not properly restrict access to the cache of Twitter
The Social subsystem in Apple iOS before 7 does not properly restrict access to the cache of Twitter icons, which allows physically proximate attackers to obtain sensitive information about recent Twitter interaction via unspecified vectors.
nvd
CVE-2013-0978P4LOWCVSS 2.1≤ 6.1.2v1.0.0+44 more2013-03-20
CVE-2013-0978 [LOW] CWE-200 CVE-2013-0978: The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 doe
The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.
nvd
CVE-2012-3735P4LOWCVSS 2.1≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3735 [LOW] CWE-200 CVE-2012-3735: The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the "Slide to
The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the "Slide to Power Off" feature, which allows physically proximate attackers to see the most recently used third-party app by watching the device's screen.
nvd
CVE-2012-3731P4LOWCVSS 2.1≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3731 [LOW] CVE-2012-3731: Mail in Apple iOS before 6 does not properly implement the Data Protection feature for e-mail attach
Mail in Apple iOS before 6 does not properly implement the Data Protection feature for e-mail attachments, which allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
nvd
CVE-2012-3739P4LOWCVSS 2.1≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3739 [LOW] CWE-264 CVE-2012-3739: The Passcode Lock implementation in Apple iOS before 6 allows physically proximate attackers to bypa
The Passcode Lock implementation in Apple iOS before 6 allows physically proximate attackers to bypass an intended passcode requirement via vectors involving use of the camera.
nvd
CVE-2012-3740P4LOWCVSS 2.1≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3740 [LOW] CWE-264 CVE-2012-3740: The Passcode Lock implementation in Apple iOS before 6 does not properly manage the lock state, whic
The Passcode Lock implementation in Apple iOS before 6 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
nvd