Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 86 of 197
CVE-2019-8734HIGHCVSS 8.8fixed in 13.02020-10-27
CVE-2019-8734 [HIGH] CWE-787 CVE-2019-8734: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, Safari 13, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-9961HIGHCVSS 7.8fixed in 14.02020-10-27
CVE-2020-9961 [HIGH] CWE-125 CVE-2020-9961: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2018-4428HIGHCVSS 7.1fixed in 12.1.12020-10-27
CVE-2018-4428 [HIGH] CVE-2018-4428: A lock screen issue allowed access to the share function on a locked device. This issue was addresse
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 12.1.1. A local attacker may be able to share items from the lock screen.
nvd
CVE-2019-8751HIGHCVSS 8.8fixed in 13.12020-10-27
CVE-2019-8751 [HIGH] CWE-787 CVE-2019-8751: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8833HIGHCVSS 7.8fixed in 13.32020-10-27
CVE-2019-8833 [HIGH] CWE-787 CVE-2019-8833: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8835HIGHCVSS 8.8fixed in 13.32020-10-27
CVE-2019-8835 [HIGH] CWE-787 CVE-2019-8835: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8592HIGHCVSS 7.8fixed in 12.3≥ 12.3.1, < 13.02020-10-27
CVE-2019-8592 [HIGH] CWE-20 CVE-2019-8592: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, tvOS 12.3, watchOS 5.2.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, iOS 13. Playing a mal
nvd
CVE-2019-8633HIGHCVSS 7.5fixed in 12.32020-10-27
CVE-2019-8633 [HIGH] CWE-20 CVE-2019-8633: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3, watchOS 5.3. An application may be able to read restricted memory.
nvd
CVE-2018-4474HIGHCVSS 7.5fixed in 12.02020-10-27
CVE-2018-4474 [HIGH] CWE-400 CVE-2018-4474: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iClou
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, watchOS 5, Safari 12, iOS 12, iTunes 12.9 for Windows, tvOS 12. Unexpected interaction causes an ASSERT failure.
nvd
CVE-2020-3880HIGHCVSS 7.8fixed in 13.3.12020-10-27
CVE-2020-3880 [HIGH] CWE-125 CVE-2020-3880: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9932HIGHCVSS 8.8fixed in 13.12020-10-27
CVE-2020-9932 [HIGH] CWE-787 CVE-2020-9932: A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0
A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8841HIGHCVSS 7.8fixed in 13.32020-10-27
CVE-2019-8841 [HIGH] CVE-2019-8841: An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed i
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8573HIGHCVSS 7.5fixed in 12.32020-10-27
CVE-2019-8573 [HIGH] CWE-20 CVE-2019-8573: An input validation issue was addressed with improved input validation. This issue is fixed in macOS
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause a system denial of service.
nvd
CVE-2019-8752HIGHCVSS 8.8fixed in 13.12020-10-27
CVE-2019-8752 [HIGH] CWE-787 CVE-2019-8752: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8709HIGHCVSS 7.8fixed in 13.02020-10-27
CVE-2019-8709 [HIGH] CWE-787 CVE-2019-8709: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8740HIGHCVSS 7.8fixed in 13.12020-10-27
CVE-2019-8740 [HIGH] CWE-787 CVE-2019-8740: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 13
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 13.1 and iPadOS 13.1, watchOS 6, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8728HIGHCVSS 8.8fixed in 13.02020-10-27
CVE-2019-8728 [HIGH] CWE-787 CVE-2019-8728: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, Safari 13, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8836HIGHCVSS 7.8fixed in 13.3.12020-10-27
CVE-2019-8836 [HIGH] CWE-787 CVE-2019-8836: A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchO
A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8844HIGHCVSS 8.8fixed in 13.32020-10-27
CVE-2019-8844 [HIGH] CWE-787 CVE-2019-8844: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8846HIGHCVSS 8.8fixed in 13.32020-10-27
CVE-2019-8846 [HIGH] CWE-416 CVE-2019-8846: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd