cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 206 of 207
CVE-2019-8682P4LOWCVSS 2.4fixed in 12.42019-12-18
CVE-2019-8682 [LOW] CWE-306 CVE-2019-8682: The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A u The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertently complete an in-app purchase while on the lock screen.
nvd
CVE-2021-30816P4LOWCVSS 2.4fixed in 15.02021-10-28
CVE-2021-30816 [LOW] CVE-2021-30816: The issue was addressed with improved permissions logic. This issue is fixed in iOS 15 and iPadOS 15 The issue was addressed with improved permissions logic. This issue is fixed in iOS 15 and iPadOS 15. An attacker with physical access to a device may be able to see private contact information.
nvd
CVE-2019-8742P4LOWCVSS 2.4fixed in 13.02019-12-18
CVE-2019-8742 [LOW] CVE-2019-8742: The issue was addressed by restricting options offered on a locked device. This issue is fixed in iO The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
CVE-2021-30815P4LOWCVSS 2.4fixed in 15.02021-10-19
CVE-2021-30815 [LOW] CVE-2021-30815: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to view contacts from the lock screen.
nvd
CVE-2024-27803P4LOWCVSS 2.4fixed in 17.52024-05-14
CVE-2024-27803 [LOW] CWE-284 CVE-2024-27803: A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPad A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.
nvd
CVE-2022-26703P4LOWCVSS 2.4fixed in 15.52022-05-26
CVE-2022-26703 [LOW] CVE-2022-26703: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.5 An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A person with physical access to an iOS device may be able to access photos from the lock screen.
nvd
CVE-2024-27819P4LOWCVSS 2.4fixed in 17.52024-06-10
CVE-2024-27819 [LOW] CWE-284 CVE-2024-27819: The issue was addressed by restricting options offered on a locked device. This issue is fixed in iO The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2022-32871P4LOWCVSS 2.4fixed in 16.02023-04-10
CVE-2022-32871 [LOW] CVE-2022-32871: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16. A person with A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16. A person with physical access to a device may be able to use Siri to access private calendar information
nvd
CVE-2024-27835P4LOWCVSS 2.4fixed in 17.52024-05-14
CVE-2024-27835 [LOW] CWE-287 CVE-2024-27835: This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.
nvd
CVE-2024-44139P4LOWCVSS 2.4fixed in 18.02024-09-17
CVE-2024-44139 [LOW] CWE-200 CVE-2024-44139: The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attack The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2022-46724P4LOWCVSS 2.4fixed in 16.42023-08-14
CVE-2022-46724 [LOW] CWE-203 CVE-2022-46724: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 16.4. A person with physical access to an iOS device may be able to view the last image used in Magnifier from the lock screen.
nvd
CVE-2024-44180P4LOWCVSS 2.4fixed in 18.02024-09-17
CVE-2024-44180 [LOW] CWE-200 CVE-2024-44180: The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attack The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2023-40529P4LOWCVSS 2.4fixed in 17.02024-01-10
CVE-2023-40529 [LOW] CVE-2023-40529: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17. A person with physical access to a device may be able to use VoiceOver to access private calendar information.
nvd
CVE-2025-43350P4LOWCVSS 2.4fixed in 26.12025-11-04
CVE-2025-43350 [LOW] CWE-276 CVE-2025-43350: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.
nvd
CVE-2024-40839P4LOWCVSS 2.4fixed in 17.52025-01-15
CVE-2024-40839 [LOW] CWE-862 CVE-2024-40839: This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.
nvd
CVE-2025-43309P4LOWCVSS 2.4fixed in 26.02025-11-04
CVE-2025-43309 [LOW] CWE-284 CVE-2025-43309: A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An at A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.
nvd
CVE-2015-1116P4LOWCVSS 2.1≤ 8.22015-04-10
CVE-2015-1116 [LOW] CWE-200 CVE-2015-1116: The UIKit View component in Apple iOS before 8.3 displays unblurred application snapshots in the Tas The UIKit View component in Apple iOS before 8.3 displays unblurred application snapshots in the Task Switcher, which makes it easier for physically proximate attackers to obtain sensitive information by reading the device screen.
nvd
CVE-2011-3429P4LOWCVSS 2.1v3.0v3.1+17 more2011-10-14
CVE-2011-3429 [LOW] CWE-255 CVE-2011-3429: The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, which might allow physically proximate attackers to obtain sensitive information by reading this file.
nvd
CVE-2011-3257P4LOWCVSS 2.1v3.0v3.1+17 more2011-10-14
CVE-2011-3257 [LOW] CWE-264 CVE-2011-3257: The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple u The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a different account's cookie.
nvd
CVE-2015-5842P4LOWCVSS 2.1≤ 8.4.12015-09-18
CVE-2015-5842 [LOW] CWE-200 CVE-2015-5842: XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.
nvd
Apple iOS vulnerabilities | cvebase