Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 203 of 207
CVE-2014-4384P4LOWCVSS 1.9≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4384 [LOW] CWE-22 CVE-2014-4384: Directory traversal vulnerability in the App Installation feature in Apple iOS before 8 allows local
Directory traversal vulnerability in the App Installation feature in Apple iOS before 8 allows local users to install unverified apps by triggering code-signature validation of an unintended bundle.
nvd
CVE-2015-1097P4LOWCVSS 1.9≤ 8.22015-04-10
CVE-2015-1097 [LOW] CWE-200 CVE-2015-1097: IOMobileFramebuffer in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to obtain sensi
IOMobileFramebuffer in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.
nvd
CVE-2014-1281P4LOWCVSS 1.9≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1281 [LOW] CWE-264 CVE-2014-1281: Photos Backend in Apple iOS before 7.1 does not properly manage the asset-library cache during delet
Photos Backend in Apple iOS before 7.1 does not properly manage the asset-library cache during deletions, which allows physically proximate attackers to obtain sensitive photo data by launching the Photos app and looking under a transparent image.
nvd
CVE-2012-3741P4LOWCVSS 1.9≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3741 [LOW] CWE-287 CVE-2012-3741: The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly hand
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that performs purchase transactions.
nvd
CVE-2015-1094P4LOWCVSS 1.9≤ 8.22015-04-10
CVE-2015-1094 [LOW] CWE-200 CVE-2015-1094: IOAcceleratorFamily in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to obtain sensi
IOAcceleratorFamily in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.
nvd
CVE-2014-4450P4LOWCVSS 1.9≤ 8.0.22014-10-22
CVE-2014-4450 [LOW] CWE-255 CVE-2014-4450: The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.
nvd
CVE-2016-4740P4LOWCVSS 2.9≤ 9.3.52016-09-18
CVE-2016-4740 [LOW] CWE-200 CVE-2016-4740: Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has o
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2025-24193P4LOWCVSS 2.4fixed in 18.42025-03-31
CVE-2025-24193 [LOW] CWE-284 CVE-2025-24193: This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18
This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.
nvd
CVE-2022-32879P4LOWCVSS 2.4fixed in 15.72022-11-01
CVE-2022-32879 [LOW] CVE-2022-32879: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13,
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, tvOS 16. A user with physical access to a device may be able to access contacts from the lock screen.
nvd
CVE-2017-2397P4LOWCVSS 2.4≤ 10.2.12017-04-02
CVE-2017-2397 [LOW] CWE-200 CVE-2017-2397: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Accounts" component. It allows physically proximate attackers to discover an Apple ID by reading an iCloud authentication prompt on the lock screen.
nvd
CVE-2022-32867P4LOWCVSS 2.4fixed in 16.02022-11-01
CVE-2022-32867 [LOW] CWE-922 CVE-2022-32867: This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.
nvd
CVE-2017-2351P4LOWCVSS 2.4≤ 10.2.02017-02-20
CVE-2017-2351 [LOW] CWE-20 CVE-2017-2351: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WiFi" component, which allows physically proximate attackers to bypass the activation-lock protection mechanism and view the home screen via unspecified vectors.
nvd
CVE-2016-7664P4LOWCVSS 2.4≤ 10.1.12017-02-20
CVE-2016-7664 [LOW] CWE-200 CVE-2016-7664: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Accessibility" component. which allows physically proximate attackers to obtain sensitive photo and contact information by leveraging the availability of excessive options during lockscreen access.
nvd
CVE-2019-8799P4LOWCVSS 2.4fixed in 13.12020-10-27
CVE-2019-8799 [LOW] CVE-2019-8799: This issue was resolved by replacing device names with a random identifier. This issue is fixed in i
This issue was resolved by replacing device names with a random identifier. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15, watchOS 6, tvOS 13. An attacker in physical proximity may be able to passively observe device names in AWDL communications.
nvd
CVE-2023-32394P4LOWCVSS 2.4fixed in 16.52023-06-23
CVE-2023-32394 [LOW] CWE-668 CVE-2023-32394: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.
nvd
CVE-2021-30915P4LOWCVSS 2.4fixed in 15.12021-08-24
CVE-2021-30915 [LOW] CVE-2021-30915: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
nvd
CVE-2017-13805P4LOWCVSS 2.4fixed in 11.12017-11-13
CVE-2017-13805 [LOW] CWE-200 CVE-2017-13805: An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to obtain sensitive information via a Siri request for private-content notifications that should not have been available in the lock-screen state.
nvd
CVE-2021-1863P4LOWCVSS 2.4fixed in 14.52021-09-08
CVE-2021-1863 [LOW] CWE-287 CVE-2021-1863: An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed wit
An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number.
nvd
CVE-2022-22599P4LOWCVSS 2.4fixed in 15.42022-03-18
CVE-2022-22599 [LOW] CVE-2022-22599: Description: A permissions issue was addressed with improved validation. This issue is fixed in watc
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.
nvd
CVE-2024-54485P4LOWCVSS 2.4fixed in 18.22024-12-12
CVE-2024-54485 [LOW] CWE-922 CVE-2024-54485: The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2,
The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.
nvd