cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 84 of 207
CVE-2026-28972P3MEDIUMCVSS 6.5fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28972 [MEDIUM] CWE-787 CVE-2026-28972: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2023-45866P3MEDIUMCVSS 6.3v16.6fixed in 17.22023-12-08
CVE-2023-45866 [MEDIUM] CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate an Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ub
nvd
CVE-2023-42849P3MEDIUMCVSS 6.5fixed in 16.7.2≥ 17.0, < 17.12023-10-25
CVE-2023-42849 [MEDIUM] CWE-119 CVE-2023-42849: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvd
CVE-2010-1387P3CRITICALCVSS 9.3≤ 3.2.1v1.0.0+22 more2010-06-18
CVE-2010-1387 [CRITICAL] CWE-399 CVE-2010-1387: Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
nvd
CVE-2015-3717P3HIGHCVSS 7.5fixed in 8.42015-07-03
CVE-2015-3717 [HIGH] CWE-120 CVE-2015-3717: Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2008-4231P3CRITICALCVSS 9.3v1.0v1.0.1+11 more2008-11-25
CVE-2008-4231 [CRITICAL] CWE-399 CVE-2008-4231: Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not prop Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
nvd
CVE-2019-6230P3HIGHCVSS 8.6fixed in 12.1.32019-03-05
CVE-2019-6230 [HIGH] CWE-665 CVE-2019-6230: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvd
CVE-2018-4330P3HIGHCVSS 7.8fixed in 11.42019-01-11
CVE-2018-4330 [HIGH] CWE-119 CVE-2018-4330: In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.
nvd
CVE-2018-4311P3HIGHCVSS 8.1fixed in 12.02019-04-03
CVE-2018-4311 [HIGH] CWE-200 CVE-2018-4311: The issue was addressed by removing origin information. This issue affected versions prior to iOS 12 The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2021-30955P3HIGHCVSS 7.0fixed in 15.22021-08-24
CVE-2021-30955 [HIGH] CWE-362 CVE-2021-30955: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1 A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2017-2389P3HIGHCVSS 8.1≤ 10.2.12017-04-02
CVE-2017-2389 [HIGH] CVE-2017-2389: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof an HTTP authentication sheet or cause a denial of service via a crafted web site.
nvd
CVE-2016-4632P3HIGHCVSS 7.5fixed in 9.3.32016-07-22
CVE-2016-4632 [HIGH] CWE-119 CVE-2016-4632: ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvd
CVE-2015-6978P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-6978 [MEDIUM] CVE-2015-6978: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvd
CVE-2022-46720P3HIGHCVSS 8.6fixed in 16.22023-05-08
CVE-2022-46720 [HIGH] CWE-190 CVE-2022-46720: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.2 an An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to break out of its sandbox
nvd
CVE-2016-1818P3HIGHCVSS 7.8≤ 9.3.12016-05-20
CVE-2016-1818 [HIGH] CVE-2016-1818: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016-1819.
nvd
CVE-2018-4100P3HIGHCVSS 7.5fixed in 11.2.52018-04-03
CVE-2018-4100 [HIGH] CWE-400 CVE-2018-4100: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
nvd
CVE-2016-4733P3HIGHCVSS 7.8fixed in 10.02016-09-25
CVE-2016-4733 [HIGH] CVE-2016-4733: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4734, and CVE-2016-4735.
nvd
CVE-2016-4650P3HIGHCVSS 7.8fixed in 9.3.22017-04-20
CVE-2016-4650 [HIGH] CWE-119 CVE-2016-4650: Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS b Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvd
CVE-2018-4343P3HIGHCVSS 7.8fixed in 12.02019-04-03
CVE-2018-4343 [HIGH] CWE-119 CVE-2018-4343: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4126P3HIGHCVSS 7.8fixed in 12.02019-04-03
CVE-2018-4126 [HIGH] CWE-119 CVE-2018-4126: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
Apple iOS vulnerabilities | cvebase