cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 35 of 207
CVE-2025-43209P3CRITICALCVSS 9.8fixed in 18.62025-07-30
CVE-2025-43209 [CRITICAL] CWE-787 CVE-2025-43209: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43347P3CRITICALCVSS 9.8fixed in 26.02025-09-15
CVE-2025-43347 [CRITICAL] CWE-20 CVE-2025-43347: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 2 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed.
nvd
CVE-2013-0340P3MEDIUMCVSS 6.8fixed in 14.82014-01-21
CVE-2013-0340 [MEDIUM] CWE-611 CVE-2013-0340: expat before version 2.4.0 does not properly handle entities expansion unless an application develop expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE
nvd
CVE-2026-43810P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43810 [CRITICAL] CWE-119 CVE-2026-43810: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43807P3CRITICALCVSS 9.8fixed in 26.5.22026-07-27
CVE-2026-43807 [CRITICAL] CWE-120 CVE-2026-43807: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.
nvd
CVE-2017-2485P3HIGHCVSS 8.8≤ 10.2.12017-04-02
CVE-2017-2485 [HIGH] CWE-416 CVE-2017-2485: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Security" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvd
CVE-2026-64726P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64726 [CRITICAL] CWE-119 CVE-2026-64726: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
nvd
CVE-2026-64751P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64751 [CRITICAL] CWE-416 CVE-2026-64751: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2018-4201P3HIGHCVSS 8.8fixed in 11.42018-06-08
CVE-2018-4201 [HIGH] CWE-119 CVE-2018-4201: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary
nvd
CVE-2017-13884P3HIGHCVSS 8.8fixed in 11.22018-04-03
CVE-2017-13884 [HIGH] CWE-119 CVE-2017-13884: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary
nvd
CVE-2017-7165P3HIGHCVSS 8.8fixed in 11.22018-04-03
CVE-2017-7165 [HIGH] CWE-119 CVE-2017-7165: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary c
nvd
CVE-2016-4728P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4728 [HIGH] CWE-20 CVE-2016-4728: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote attackers to execute arbitrary code via a crafted web site.
nvd
CVE-2018-4122P3HIGHCVSS 8.8fixed in 11.32018-04-03
CVE-2018-4122 [HIGH] CWE-119 CVE-2018-4122: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvd
CVE-2018-4129P3HIGHCVSS 8.8fixed in 11.32018-04-03
CVE-2018-4129 [HIGH] CWE-119 CVE-2018-4129: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvd
CVE-2018-4125P3HIGHCVSS 8.8fixed in 11.32018-04-03
CVE-2018-4125 [HIGH] CWE-119 CVE-2018-4125: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvd
CVE-2018-4163P3HIGHCVSS 8.8fixed in 11.32018-04-03
CVE-2018-4163 [HIGH] CWE-119 CVE-2018-4163: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvd
CVE-2018-4114P3HIGHCVSS 8.8fixed in 11.32018-04-03
CVE-2018-4114 [HIGH] CWE-119 CVE-2018-4114: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvd
CVE-2019-8523P3HIGHCVSS 8.8fixed in 12.22019-12-18
CVE-2019-8523 [HIGH] CWE-787 CVE-2019-8523: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2017-2444P3HIGHCVSS 8.8≤ 10.2.12017-04-02
CVE-2017-2444 [HIGH] CWE-119 CVE-2017-2444: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvd
CVE-2019-6201P3HIGHCVSS 8.8fixed in 12.22019-12-18
CVE-2019-6201 [HIGH] CWE-787 CVE-2019-6201: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
Apple iOS vulnerabilities | cvebase