Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 204 of 207
CVE-2024-44179P4LOWCVSS 2.4fixed in 17.72025-03-10
CVE-2024-44179 [LOW] CWE-200 CVE-2024-44179: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to a device may be able to read contact numbers from the lock screen.
nvd
CVE-2024-44251P4LOWCVSS 2.4fixed in 18.12024-10-28
CVE-2024-44251 [LOW] CVE-2024-44251: This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.
nvd
CVE-2022-46717P4LOWCVSS 2.4fixed in 16.22023-04-10
CVE-2022-46717 [LOW] CVE-2022-46717: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2. A user with physical access to a locked Apple Watch may be able to view user photos via accessibility features
nvd
CVE-2025-30469P4LOWCVSS 2.4fixed in 18.42025-03-31
CVE-2025-30469 [LOW] CWE-863 CVE-2025-30469: This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person with physical access to an iOS device may be able to access photos from the lock screen.
nvd
CVE-2024-40851P4LOWCVSS 2.4fixed in 18.12024-10-28
CVE-2024-40851 [LOW] CVE-2024-40851: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.
nvd
CVE-2024-54556P4LOWCVSS 2.4fixed in 18.12026-01-16
CVE-2024-54556 [LOW] CWE-284 CVE-2024-54556: This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may be able to view restricted content from the lock screen.
nvd
CVE-2025-31216P4LOWCVSS 2.4fixed in 18.52025-11-21
CVE-2025-31216 [LOW] CWE-284 CVE-2025-31216: The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.
nvd
CVE-2026-20642P4LOWCVSS 2.4fixed in 26.32026-02-11
CVE-2026-20642 [LOW] CWE-284 CVE-2026-20642: An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person w
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access photos from the lock screen.
nvd
CVE-2014-4356P4LOWCVSS 2.1≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4356 [LOW] CWE-200 CVE-2014-4356: Apple iOS before 8 does not follow the intended configuration setting for text-message preview on th
Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which allows physically proximate attackers to obtain sensitive information by reading this screen.
nvd
CVE-2015-1109P4LOWCVSS 2.1≤ 8.22015-04-10
CVE-2015-1109 [LOW] CWE-200 CVE-2015-1109: NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes i
NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.
nvd
CVE-2011-3245P4LOWCVSS 2.1v3.0v3.1+17 more2011-10-14
CVE-2011-3245 [LOW] CWE-255 CVE-2011-3245: The Keyboards component in Apple iOS before 5 displays the final character of an entered password du
The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.
nvd
CVE-2015-7000P4LOWCVSS 2.1≤ 9.0.22015-10-23
CVE-2015-7000 [LOW] CWE-200 CVE-2015-7000: Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, wh
Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon after a setting was disabled.
nvd
CVE-2014-4367P4LOWCVSS 2.1≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4367 [LOW] CWE-264 CVE-2014-4367: Apple iOS before 8 enables Voice Dial during all upgrade actions, which makes it easier for physical
Apple iOS before 8 enables Voice Dial during all upgrade actions, which makes it easier for physically proximate attackers to launch unintended calls by speaking a telephone number.
nvd
CVE-2013-0980P4LOWCVSS 2.1≤ 6.1.2v1.0.0+44 more2013-03-20
CVE-2013-0980 [LOW] CWE-264 CVE-2013-0980: The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state,
The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging an error in the emergency-call feature.
nvd
CVE-2014-1274P4LOWCVSS 2.1≤ 7.0.6v7.0+5 more2014-03-14
CVE-2014-1274 [LOW] CWE-200 CVE-2014-1274: FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime
FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call.
nvd
CVE-2015-5851P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5851 [LOW] CWE-200 CVE-2015-5851: The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not r
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.
nvd
CVE-2014-1348P4LOWCVSS 2.1≤ 7.1.1v7.0+7 more2014-07-01
CVE-2014-1348 [LOW] CWE-310 CVE-2014-1348: Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but st
Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting the data partition.
nvd
CVE-2014-4357P4LOWCVSS 2.1≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4357 [LOW] CWE-200 CVE-2014-4357: Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.
nvd
CVE-2015-5863P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5863 [LOW] CWE-200 CVE-2015-5863: IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, wh
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
nvd
CVE-2015-5898P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5898 [LOW] CWE-200 CVE-2015-5898: CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
nvd