Apple iOS vulnerabilities
4,050 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,050
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL314HIGH1660MEDIUM1787LOW289
Vulnerabilities
Page 5 of 203
CVE-2019-7287P1HIGHCVSS 7.8KEVfixed in 12.1.42019-12-18
CVE-2019-7287 [HIGH] CWE-787 CVE-2019-7287: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-38606P1MEDIUMCVSS 5.5KEVfixed in 15.7.8≥ 16.0, < 16.62023-07-27
CVE-2023-38606 [MEDIUM] CVE-2023-38606: This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.
This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited again
nvd
CVE-2025-43510P1HIGHCVSS 7.8KEVfixed in 18.7.2v26.02025-12-12
CVE-2025-43510 [HIGH] CWE-667 CVE-2025-43510: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
nvd
CVE-2018-4344P2HIGHCVSS 7.8KEVfixed in 12.02019-04-03
CVE-2018-4344 [HIGH] CWE-119 CVE-2018-4344: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2021-31010P2HIGHCVSS 7.5KEV≥ 12.0, < 12.5.5≥ 14.0, < 14.82021-08-24
CVE-2021-31010 [HIGH] CWE-502 CVE-2021-31010: A deserialization issue was addressed through improved validation. This issue is fixed in Security U
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the tim
nvd
CVE-2021-1879P1MEDIUMCVSS 6.1KEVfixed in 12.5.2≥ 13.0, < 14.4.22021-04-02
CVE-2021-1879 [MEDIUM] CWE-79 CVE-2021-1879: This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2025-43520P1MEDIUMCVSS 5.5KEVfixed in 18.7.2v26.02025-12-12
CVE-2025-43520 [MEDIUM] CWE-120 CVE-2025-43520: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2025-24200P2MEDIUMCVSS 6.1KEVfixed in 15.8.4≥ 16.0, < 16.7.11+1 more2025-02-10
CVE-2025-24200 [MEDIUM] CWE-863 CVE-2025-24200: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely
nvd
CVE-2025-43200P2MEDIUMCVSS 4.2KEVfixed in 15.8.4≥ 16.0, ≤ 16.7.11+1 more2025-06-16
CVE-2025-43200 [MEDIUM] CVE-2025-43200: This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4,
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via
nvd
CVE-2021-30983P2HIGHCVSS 7.8KEVfixed in 15.22021-08-24
CVE-2021-30983 [HIGH] CWE-120 CVE-2021-30983: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-6223P2HIGHCVSS 7.5KEVfixed in 12.1.42019-03-05
CVE-2019-6223 [HIGH] CVE-2019-6223: A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.
nvd
CVE-2020-9819P2MEDIUMCVSS 4.3KEVfixed in 12.4.7≥ 13.0, < 13.52020-06-09
CVE-2020-9819 [MEDIUM] CWE-787 CVE-2020-9819: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 1
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.
nvd
CVE-2018-4233P1HIGHCVSS 8.8ExploitedPoCfixed in 11.42018-06-08
CVE-2018-4233 [HIGH] CWE-119 CVE-2018-4233: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary
nvd
CVE-2022-46689P1HIGHCVSS 7.0ExploitedPoCfixed in 15.7.2≥ 16.0, < 16.1.22022-12-15
CVE-2022-46689 [HIGH] CWE-362 CVE-2022-46689: A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS M
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8646P1HIGHCVSS 7.5ExploitedPoCRansomwarefixed in 12.42019-12-18
CVE-2019-8646 [HIGH] CWE-125 CVE-2019-8646: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to leak memory.
nvd
CVE-2010-1797P2CRITICALCVSS 9.3ExploitedPoCv1.0.0v1.0.1+24 more2010-08-16
CVE-2010-1797 [CRITICAL] CWE-119 CVE-2010-1797: Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory cor
nvd
CVE-2022-42864P1HIGHCVSS 7.0ExploitedPoCfixed in 15.7.2≥ 16.0, < 16.22022-12-15
CVE-2022-42864 [HIGH] CWE-362 CVE-2022-42864: A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-9802P1HIGHCVSS 8.8ExploitedPoCfixed in 13.52020-06-09
CVE-2020-9802 [HIGH] CVE-2020-9802: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2018-4404P1HIGHCVSS 8.8ExploitedPoCfixed in 11.42019-01-11
CVE-2018-4404 [HIGH] CWE-119 CVE-2018-4404: In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was ad
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.
nvd
CVE-2024-44258P1HIGHCVSS 7.1ExploitedPoCfixed in 17.7.1≥ 18.0, < 18.12024-10-28
CVE-2024-44258 [HIGH] CWE-59 CVE-2024-44258: This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and i
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd