cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 87 of 207
CVE-2025-24129P3HIGHCVSS 7.5fixed in 18.32025-01-27
CVE-2025-24129 [HIGH] CWE-843 CVE-2025-24129: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadO A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may cause an unexpected app termination.
nvd
CVE-2015-3776P3CRITICALCVSS 9.3≤ 8.42015-08-16
CVE-2015-3776 [CRITICAL] CWE-119 CVE-2015-3776: IOKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code i IOKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption and application crash) via a malformed plist.
nvd
CVE-2013-1003P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1003 [CRITICAL] CWE-399 CVE-2013-1003: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1006P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1006 [CRITICAL] CWE-399 CVE-2013-1006: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1004P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1004 [CRITICAL] CWE-399 CVE-2013-1004: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1008P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1008 [CRITICAL] CWE-399 CVE-2013-1008: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1001P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1001 [CRITICAL] CWE-399 CVE-2013-1001: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1000P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1000 [CRITICAL] CWE-119 CVE-2013-1000: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1005P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1005 [CRITICAL] CWE-399 CVE-2013-1005: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-0999P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-0999 [CRITICAL] CWE-119 CVE-2013-0999: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1007P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1007 [CRITICAL] CWE-399 CVE-2013-1007: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1002P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1002 [CRITICAL] CWE-399 CVE-2013-1002: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2013-1010P3CRITICALCVSS 9.3≤ 6.1.4v1.0.0+46 more2013-05-20
CVE-2013-1010 [CRITICAL] CWE-399 CVE-2013-1010: WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitra WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
nvd
CVE-2025-43372P3HIGHCVSS 7.8fixed in 26.02025-09-15
CVE-2025-43372 [HIGH] CWE-20 CVE-2025-43372: The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2022-22643P3HIGHCVSS 7.5fixed in 15.42022-03-18
CVE-2022-22643 [HIGH] CVE-2022-22643: This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macO This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A user may send audio and video in a FaceTime call without knowing that they have done so.
nvd
CVE-2018-4329P3HIGHCVSS 7.5fixed in 12.02019-04-03
CVE-2018-4329 [HIGH] CWE-19 CVE-2018-4329: Clearing a history item may not clear visits with redirect chains. The issue was addressed with impr Clearing a history item may not clear visits with redirect chains. The issue was addressed with improved data deletion. This issue affected versions prior to iOS 12, Safari 12.
nvd
CVE-2009-3271P4MEDIUMCVSS 4.3PoCv3.0.12009-09-21
CVE-2009-3271 [MEDIUM] CWE-20 CVE-2009-3271: Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application cr Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.
nvd
CVE-2020-9854P3HIGHCVSS 7.8fixed in 13.52020-10-22
CVE-2020-9854 [HIGH] CVE-2020-9854: A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13. A logic issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. An application may be able to gain elevated privileges.
nvd
CVE-2022-42850P3HIGHCVSS 7.8fixed in 16.22022-12-15
CVE-2022-42850 [HIGH] CWE-787 CVE-2022-42850: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2017-7133P3HIGHCVSS 7.5≤ 10.3.32017-10-23
CVE-2017-7133 [HIGH] CWE-319 CVE-2017-7133: An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "MobileBackup" component. It allows remote attackers to obtain sensitive cleartext information in opportunistic circumstances by leveraging read access to a backup archive that was supposed to have been encrypted.
nvd