Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 77 of 197
CVE-2021-30967MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30967 [MEDIUM] CVE-2021-30967: Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS
Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPadOS 15.2. A local attacker may be able to read sensitive information.
nvd
CVE-2021-30968MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30968 [MEDIUM] CWE-59 CVE-2021-30968: A validation issue related to hard link behavior was addressed with improved sandbox restrictions. T
A validation issue related to hard link behavior was addressed with improved sandbox restrictions. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2021-30910MEDIUMCVSS 5.5fixed in 15.12021-08-24
CVE-2021-30910 [MEDIUM] CWE-125 CVE-2021-30910: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.1 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted file may disclose user information.
nvd
CVE-2021-30897MEDIUMCVSS 6.5fixed in 15.02021-08-24
CVE-2021-30897 [MEDIUM] CVE-2021-30897: An issue existed in the specification for the resource timing API. The specification was updated and
An issue existed in the specification for the resource timing API. The specification was updated and the updated specification was implemented. This issue is fixed in macOS Monterey 12.0.1. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2021-30988MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30988 [MEDIUM] CVE-2021-30988: Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS
Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPadOS 15.2. A malicious application may be able to identify what other applications a user has installed.
nvd
CVE-2021-31013MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-31013 [MEDIUM] CWE-125 CVE-2021-31013: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mont
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2021-30863MEDIUMCVSS 6.8fixed in 15.02021-08-24
CVE-2021-30863 [MEDIUM] CVE-2021-30863: This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 15 an
This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 15 and iPadOS 15. A 3D model constructed to look like the enrolled user may be able to authenticate via Face ID.
nvd
CVE-2021-30921MEDIUMCVSS 5.5fixed in 14.52021-08-24
CVE-2021-30921 [MEDIUM] CWE-668 CVE-2021-30921: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible onscreen.
nvd
CVE-2021-30964MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30964 [MEDIUM] CWE-732 CVE-2021-30964: An inherited permissions issue was addressed with additional restrictions. This issue is fixed in ma
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2021-30867MEDIUMCVSS 5.5fixed in 15.02021-08-24
CVE-2021-30867 [MEDIUM] CWE-287 CVE-2021-30867: The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A
The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos.
nvd
CVE-2021-30870MEDIUMCVSS 6.5fixed in 15.02021-08-24
CVE-2021-30870 [MEDIUM] CVE-2021-30870: A logic issue existed in the handling of document loads. This issue was addressed with improved stat
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. Previewing an html file attached to a note may unexpectedly contact remote servers.
nvd
CVE-2021-30973MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30973 [MEDIUM] CWE-125 CVE-2021-30973: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Mon
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted file may disclose user information.
nvd
CVE-2021-30944MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30944 [MEDIUM] CVE-2021-30944: Description: A logic issue was addressed with improved state management. This issue is fixed in iOS
Description: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1, tvOS 15.2. A malicious app may be able to access data from other apps by enabling additional logging.
nvd
CVE-2021-30941MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30941 [MEDIUM] CWE-120 CVE-2021-30941: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina. Processing a maliciously crafted USD file may disclose memory contents.
nvd
CVE-2021-30960MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30960 [MEDIUM] CWE-120 CVE-2021-30960: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
nvd
CVE-2021-30887MEDIUMCVSS 6.5fixed in 15.12021-08-24
CVE-2021-30887 [MEDIUM] CVE-2021-30887: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy.
nvd
CVE-2021-30946MEDIUMCVSS 5.5fixed in 15.22021-08-24
CVE-2021-30946 [MEDIUM] CVE-2021-30946: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1,
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2021-30932MEDIUMCVSS 4.6fixed in 15.22021-08-24
CVE-2021-30932 [MEDIUM] CVE-2021-30932: The issue was addressed with improved permissions logic. This issue is fixed in iOS 15.2 and iPadOS
The issue was addressed with improved permissions logic. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
CVE-2021-30871MEDIUMCVSS 5.5fixed in 14.72021-08-24
CVE-2021-30871 [MEDIUM] CVE-2021-30871: This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS
This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS Big Sur 11.5. A local attacker may be able to access analytics data.
nvd
CVE-2021-30915LOWCVSS 2.4fixed in 15.12021-08-24
CVE-2021-30915 [LOW] CVE-2021-30915: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
nvd