Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 74 of 207
CVE-2026-28872P3HIGHCVSS 7.5fixed in 18.7.9≥ 26.0, < 26.42026-05-11
CVE-2026-28872 [HIGH] CWE-400 CVE-2026-28872: A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2026-28943P3HIGHCVSS 7.5fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28943 [HIGH] CWE-532 CVE-2026-28943: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iP
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to determine kernel memory layout.
nvd
CVE-2025-43454P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43454 [HIGH] CWE-284 CVE-2025-43454: This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iP
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. A device may persistently fail to lock.
nvd
CVE-2025-43449P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43449 [HIGH] CWE-200 CVE-2025-43449: The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS
The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious app may be able to track users between installs.
nvd
CVE-2026-28929P3HIGHCVSS 7.5fixed in 18.7.92026-05-11
CVE-2026-28929 [HIGH] CWE-1254 CVE-2026-28929: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode.
nvd
CVE-2026-28944P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28944 [HIGH] CWE-119 CVE-2026-28944: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43450P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43450 [HIGH] CWE-284 CVE-2025-43450: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to learn information about the current camera view before being granted camera access.
nvd
CVE-2026-28964P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28964 [HIGH] CWE-451 CVE-2026-28964: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to access sensitive user data.
nvd
CVE-2025-46311P3HIGHCVSS 7.5fixed in 18.7.3≥ 26.0, < 26.22026-05-12
CVE-2025-46311 [HIGH] CWE-451 CVE-2025-46311: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitive user data.
nvd
CVE-2026-20649P3HIGHCVSS 7.5fixed in 26.32026-02-11
CVE-2026-20649 [HIGH] CWE-377 CVE-2026-20649: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPad
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.
nvd
CVE-2020-6514P3MEDIUMCVSS 6.5fixed in 13.62020-07-22
CVE-2020-6514 [MEDIUM] CWE-200 CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
nvd
CVE-2026-64740P3CRITICALCVSS 9.3fixed in 26.62026-07-27
CVE-2026-64740 [CRITICAL] CWE-22 CVE-2026-64740: A parsing issue in the handling of directory paths was addressed with improved path validation. This
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.
nvd
CVE-2015-5874P3HIGHCVSS 7.5≤ 8.4.12015-09-18
CVE-2015-5874 [HIGH] CWE-119 CVE-2015-5874: CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary c
CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvd
CVE-2011-1344P3MEDIUMCVSS 6.8≤ 4.3.1v1.0.0+34 more2011-03-10
CVE-2011-1344 [MEDIUM] CWE-399 CVE-2011-1344: Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for i
Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding children to a WBR tag and then removing the tag, related to text nodes, as demonstrated by Chaouki Bekra
nvd
CVE-2018-4354P3HIGHCVSS 8.6fixed in 12.02019-04-03
CVE-2018-4354 [HIGH] CWE-119 CVE-2018-4354: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4341P3HIGHCVSS 8.6fixed in 12.02019-04-03
CVE-2018-4341 [HIGH] CWE-119 CVE-2018-4341: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2015-5775P3HIGHCVSS 7.5≤ 8.42015-08-17
CVE-2015-5775 [HIGH] CVE-2015-5775: FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbi
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5756.
nvd
CVE-2015-3804P3HIGHCVSS 7.5≤ 8.42015-08-17
CVE-2015-3804 [HIGH] CWE-119 CVE-2015-3804: FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbi
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5756 and CVE-2015-5775.
nvd
CVE-2008-3612P3CRITICALCVSS 9.8≥ 2.0.0, ≤ 2.0.22008-09-11
CVE-2008-3612 [CRITICAL] CWE-330 CVE-2008-3612: The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses p
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
nvd
CVE-2014-4495P3CRITICALCVSS 10.0≤ 8.1.22015-01-30
CVE-2014-4495 [CRITICAL] CWE-264 CVE-2014-4495: The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not
The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restrictions via a crafted app.
nvd