cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 205 of 207
CVE-2025-43423P4LOWCVSS 2.0fixed in 26.12025-11-04
CVE-2025-43423 [LOW] CWE-532 CVE-2025-43423: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iP A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlocked device paired with a Mac may be able to view sensitive user information in system logging.
nvd
CVE-2013-5150P4LOWCVSS 1.9≤ 6.1.4v1.0.0+46 more2013-09-19
CVE-2013-5150 [LOW] CWE-200 CVE-2013-5150: The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history of an open tab, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.
nvd
CVE-2015-1064P4LOWCVSS 1.9≤ 8.1.32015-03-12
CVE-2015-1064 [LOW] CWE-200 CVE-2015-1064: Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended acti Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended activation requirement and read the home screen by leveraging an application crash during the activation process.
nvd
CVE-2012-3729P4LOWCVSS 1.9≤ 5.1.1v1.0.0+38 more2012-09-20
CVE-2012-3729 [LOW] CWE-264 CVE-2012-3729: The Berkeley Packet Filter (BPF) interpreter implementation in the kernel in Apple iOS before 6 acce The Berkeley Packet Filter (BPF) interpreter implementation in the kernel in Apple iOS before 6 accesses uninitialized memory locations, which allows local users to obtain sensitive information about the layout of kernel memory via a crafted program that uses a BPF interface.
nvd
CVE-2014-4448P4LOWCVSS 1.9≤ 8.0.22014-10-22
CVE-2014-4448 [LOW] CWE-310 CVE-2014-4448: House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.
nvd
CVE-2022-32870P4LOWCVSS 2.4fixed in 16.02022-11-01
CVE-2022-32870 [LOW] CWE-200 CVE-2022-32870: A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ven A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.
nvd
CVE-2018-4123P4LOWCVSS 2.4fixed in 11.32018-04-03
CVE-2018-4123 [LOW] CWE-200 CVE-2018-4123: An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves a An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves alarm and timer handling in the "Clock" component. It allows physically proximate attackers to discover the iTunes e-mail address.
nvd
CVE-2017-7058P4LOWCVSS 2.4≤ 10.3.22017-07-20
CVE-2017-7058 [LOW] CWE-200 CVE-2017-7058: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Notifications" component. It allows physically proximate attackers to read unintended notifications on the lock screen.
nvd
CVE-2016-1852P4LOWCVSS 2.4≤ 9.3.12016-05-20
CVE-2016-1852 [LOW] CWE-200 CVE-2016-1852: Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.
nvd
CVE-2016-7653P4LOWCVSS 2.4≤ 10.1.12017-02-20
CVE-2016-7653 [LOW] CWE-200 CVE-2016-7653: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Media Player" component, which allows physically proximate attackers to obtain sensitive photo and contact information by leveraging lockscreen access.
nvd
CVE-2022-32872P4LOWCVSS 2.4fixed in 15.72022-09-20
CVE-2022-32872 [LOW] CWE-284 CVE-2022-32872: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.
nvd
CVE-2021-30918P4LOWCVSS 2.4fixed in 14.8.1v15.02021-08-24
CVE-2021-30918 [LOW] CVE-2021-30918: A Lock Screen issue was addressed with improved state management. This issue is fixed in iOS 14.8.1 A Lock Screen issue was addressed with improved state management. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.0.1 and iPadOS 15.0.1. A user may be able to view restricted content from the Lock Screen.
nvd
CVE-2021-1862P4LOWCVSS 2.4fixed in 14.52021-09-08
CVE-2021-1862 [LOW] CVE-2021-1862: Description: A person with physical access may be able to access contacts. This issue is fixed in iO Description: A person with physical access may be able to access contacts. This issue is fixed in iOS 14.5 and iPadOS 14.5. Impact: An issue with Siri search access to information was addressed with improved logic.
nvd
CVE-2021-1756P4LOWCVSS 2.4fixed in 14.42021-04-02
CVE-2021-1756 [LOW] CVE-2021-1756: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker with physical access to a device may be able to see private contact information.
nvd
CVE-2020-3859P4LOWCVSS 2.4fixed in 13.3.12020-02-27
CVE-2020-3859 [LOW] CVE-2020-3859: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
CVE-2016-7765P4LOWCVSS 2.4≤ 10.1.12017-02-20
CVE-2016-7765 [LOW] CWE-200 CVE-2016-7765: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Clipboard" component, which allows physically proximate attackers to obtain sensitive information in the lockscreen state by viewing clipboard contents.
nvd
CVE-2018-4238P4LOWCVSS 2.4fixed in 11.42018-06-08
CVE-2018-4238 [LOW] CWE-732 CVE-2018-4238: An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to bypass the lock-screen protection mechanism and enable Siri.
nvd
CVE-2019-8599P4LOWCVSS 2.4fixed in 12.32019-12-18
CVE-2019-8599 [LOW] CVE-2019-8599: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 12.3. A person wi A logic issue was addressed with improved restrictions. This issue is fixed in iOS 12.3. A person with physical access to an iOS device may be able to see the email address used for iTunes.
nvd
CVE-2017-7139P4LOWCVSS 2.4≤ 10.3.32017-10-23
CVE-2017-7139 [LOW] CWE-200 CVE-2017-7139: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Phone" component. It allows attackers to obtain sensitive information by leveraging a timing bug to read a secure-content screenshot that occurred during a locking action.
nvd
CVE-2019-8732P4LOWCVSS 2.4fixed in 13.02020-10-27
CVE-2019-8732 [LOW] CWE-459 CVE-2019-8732: The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls re The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls remained visible on the device.
nvd
Apple iOS vulnerabilities | cvebase