Apple iOS vulnerabilities

3,940 known vulnerabilities affecting apple/iphone_os.

Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287

Vulnerabilities

Page 29 of 197
CVE-2024-40788MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40788 [MEDIUM] CWE-843 CVE-2024-40788: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7. A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to cause unexpected system shutdown.
nvd
CVE-2024-40824MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40824 [MEDIUM] CWE-281 CVE-2024-40824: This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.
nvd
CVE-2024-27884MEDIUMCVSS 5.5fixed in 17.52024-07-29
CVE-2024-27884 [MEDIUM] CWE-200 CVE-2024-27884: This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, ma This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to access user-sensitive data.
nvd
CVE-2024-40813MEDIUMCVSS 4.6fixed in 17.62024-07-29
CVE-2024-40813 [MEDIUM] CWE-922 CVE-2024-40813: A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 an A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2024-40806MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40806 [MEDIUM] CWE-125 CVE-2024-40806: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2024-40782MEDIUMCVSS 6.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40782 [MEDIUM] CWE-416 CVE-2024-40782: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2024-40829MEDIUMCVSS 4.6fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40829 [MEDIUM] CWE-416 CVE-2024-40829: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, i The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker may be able to view restricted content from the lock screen.
nvd
CVE-2024-27823MEDIUMCVSS 5.9fixed in 16.7.8≥ 17.0, < 17.52024-07-29
CVE-2024-27823 [MEDIUM] CWE-362 CVE-2024-27823: A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 1 A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network position may be able to spoof network packets.
nvd
CVE-2024-27863MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-27863 [MEDIUM] CVE-2024-27863: An information disclosure issue was addressed with improved private data redaction for log entries. An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to determine kernel memory layout.
nvd
CVE-2024-40785MEDIUMCVSS 6.1fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40785 [MEDIUM] CWE-79 CVE-2024-40785: This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iP This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2024-40793MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40793 [MEDIUM] CWE-200 CVE-2024-40793: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPad This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An app may be able to access user-sensitive data.
nvd
CVE-2024-27873MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-27873 [MEDIUM] CWE-787 CVE-2024-27873: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Processing a maliciously crafted video file may lead to unexpected app termination.
nvd
CVE-2024-40777MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40777 [MEDIUM] CWE-787 CVE-2024-40777: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2024-40776MEDIUMCVSS 4.3fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40776 [MEDIUM] CWE-416 CVE-2024-40776: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2024-40836MEDIUMCVSS 5.5fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40836 [MEDIUM] CWE-200 CVE-2024-40836: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.
nvd
CVE-2024-40794MEDIUMCVSS 5.3fixed in 17.62024-07-29
CVE-2024-40794 [MEDIUM] CWE-287 CVE-2024-40794: This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.
nvd
CVE-2024-40778LOWCVSS 3.3fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40778 [LOW] CWE-287 CVE-2024-40778: An authentication issue was addressed with improved state management. This issue is fixed in iOS 16. An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Photos in the Hidden Photos Album may be viewed without authentication.
nvd
CVE-2023-42925LOWCVSS 3.3fixed in 17.02024-07-29
CVE-2023-42925 [LOW] CWE-200 CVE-2023-42925: The issue was addressed with improved restriction of data container access. This issue is fixed in i The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access Notes attachments.
nvd
CVE-2024-40822LOWCVSS 2.4fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40822 [LOW] CWE-284 CVE-2024-40822: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen.
nvd
CVE-2024-40795LOWCVSS 3.3fixed in 17.62024-07-29
CVE-2024-40795 [LOW] CVE-2024-40795: This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 1 This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to read sensitive location information.
nvd