Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 43 of 207
CVE-2017-7093P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7093 [HIGH] CWE-119 CVE-2017-7093: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7091P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7091 [HIGH] CWE-119 CVE-2017-7091: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7104P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7104 [HIGH] CWE-119 CVE-2017-7104: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7098P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7098 [HIGH] CWE-119 CVE-2017-7098: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7081P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7081 [HIGH] CWE-119 CVE-2017-7081: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7094P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7094 [HIGH] CWE-119 CVE-2017-7094: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7100P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7100 [HIGH] CWE-119 CVE-2017-7100: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7087P3HIGHCVSS 8.8≤ 10.3.32017-10-23
CVE-2017-7087 [HIGH] CWE-119 CVE-2017-7087: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c
nvd
CVE-2017-7020P3HIGHCVSS 8.8fixed in 10.3.32017-07-20
CVE-2017-7020 [HIGH] CWE-119 CVE-2017-7020: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvd
CVE-2021-30939P3HIGHCVSS 7.8fixed in 15.22021-08-24
CVE-2021-30939 [HIGH] CWE-125 CVE-2021-30939: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2018-4085P3HIGHCVSS 8.8fixed in 11.2.52018-04-03
CVE-2018-4085 [HIGH] CWE-119 CVE-2018-4085: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "QuartzCore" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) vi
nvd
CVE-2017-7052P3HIGHCVSS 8.8fixed in 10.3.32017-07-20
CVE-2017-7052 [HIGH] CWE-119 CVE-2017-7052: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of s
nvd
CVE-2016-7578P3HIGHCVSS 8.8fixed in 10.12017-02-20
CVE-2016-7578 [HIGH] CWE-119 CVE-2016-7578: An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
nvd
CVE-2019-9506P3HIGHCVSS 8.1v12.42019-08-14
CVE-2019-9506 [HIGH] CWE-310 CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encrypti
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
nvd
CVE-2021-36690P3HIGHCVSS 7.5fixed in 16.02021-08-24
CVE-2021-36690 [HIGH] CVE-2021-36690: A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the id
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem
nvd
CVE-2024-54525P3HIGHCVSS 8.8fixed in 18.22025-03-17
CVE-2024-54525 [HIGH] CWE-434 CVE-2024-54525: A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS
A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2021-30835P3HIGHCVSS 7.8fixed in 15.02021-10-19
CVE-2021-30835 [HIGH] CVE-2021-30835: This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catal
This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2017-2513P3CRITICALCVSS 9.8≤ 10.3.12017-05-22
CVE-2017-2513 [CRITICAL] CWE-416 CVE-2017-2513: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application cra
nvd
CVE-2016-4614P3CRITICALCVSS 9.8fixed in 9.3.32016-07-22
CVE-2016-4614 [CRITICAL] CWE-787 CVE-2016-4614: libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo
libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4615, CVE-
nvd
CVE-2016-4616P3CRITICALCVSS 9.8fixed in 9.3.32016-07-22
CVE-2016-4616 [CRITICAL] CVE-2016-4616: libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo
libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-461
nvd