Apple iOS vulnerabilities
3,940 known vulnerabilities affecting apple/iphone_os.
Total CVEs
3,940
CISA KEV
92
actively exploited
Public exploits
248
Exploited in wild
79
Severity breakdown
CRITICAL313HIGH1610MEDIUM1730LOW287
Vulnerabilities
Page 88 of 197
CVE-2019-8532MEDIUMCVSS 5.5fixed in 12.22020-10-27
CVE-2019-8532 [MEDIUM] CVE-2019-8532: A permissions issue was addressed by removing vulnerable code and adding additional checks. This iss
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in watchOS 5.2, iOS 12.2. A malicious application may be able to access restricted files.
nvd
CVE-2019-8780MEDIUMCVSS 5.5fixed in 13.12020-10-27
CVE-2019-8780 [MEDIUM] CVE-2019-8780: The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.1 and iPadOS
The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2018-4390MEDIUMCVSS 5.5fixed in 12.12020-10-27
CVE-2018-4390 [MEDIUM] CVE-2018-4390: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing.
nvd
CVE-2018-4444MEDIUMCVSS 6.5fixed in 12.1.12020-10-27
CVE-2018-4444 [MEDIUM] CVE-2018-4444: A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iO
A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.1, iTunes 12.9.2 for Windows. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2020-9979MEDIUMCVSS 5.5fixed in 14.02020-10-27
CVE-2020-9979 [MEDIUM] CVE-2020-9979: A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.
A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.
nvd
CVE-2018-4391MEDIUMCVSS 5.5fixed in 12.12020-10-27
CVE-2018-4391 [MEDIUM] CVE-2018-4391: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan, watchOS 4.3, iOS 12.1. Processing a maliciously crafted text message may lead to UI spoofing.
nvd
CVE-2019-8753MEDIUMCVSS 6.1fixed in 13.12020-10-27
CVE-2019-8753 [MEDIUM] CWE-79 CVE-2019-8753: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2019-8796MEDIUMCVSS 5.3fixed in 12.4.3≥ 13.0, < 13.22020-10-27
CVE-2019-8796 [MEDIUM] CVE-2019-8796: A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1,
A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, iOS 12.4.3, watchOS 6.1, iOS 13.2 and iPadOS 13.2. AirDrop transfers may be unexpectedly accepted while in Everyone mode.
nvd
CVE-2019-8898MEDIUMCVSS 4.3fixed in 13.32020-10-27
CVE-2019-8898 [MEDIUM] CVE-2019-8898: An information disclosure issue existed in the handling of the Storage Access API. This issue was ad
An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
nvd
CVE-2019-8762MEDIUMCVSS 6.1fixed in 13.12020-10-27
CVE-2019-8762 [MEDIUM] CWE-79 CVE-2019-8762: A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1
A validation issue was addressed with improved logic. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, tvOS 13, iCloud for Windows 7.14, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2019-8570MEDIUMCVSS 6.5fixed in 12.1.32020-10-27
CVE-2019-8570 [MEDIUM] CVE-2019-8570: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iClou
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iCloud for Windows 7.10, iTunes 12.9.3 for Windows, Safari 12.0.3, tvOS 12.1.2. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2019-8771MEDIUMCVSS 6.1fixed in 13.0.2020-10-27
CVE-2019-8771 [MEDIUM] CWE-1021 CVE-2019-8771: This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.
nvd
CVE-2019-8708MEDIUMCVSS 5.5fixed in 13.02020-10-27
CVE-2019-8708 [MEDIUM] CVE-2019-8708: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15, iOS 13. A local user may be able to check for the existence of arbitrary files.
nvd
CVE-2019-8834MEDIUMCVSS 4.3fixed in 13.32020-10-27
CVE-2019-8834 [MEDIUM] CVE-2019-8834: A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3,
A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An attacker in a privileged network position
nvd
CVE-2019-8901MEDIUMCVSS 6.5fixed in 13.12020-10-27
CVE-2019-8901 [MEDIUM] CWE-347 CVE-2019-8901: This issue was addressed by verifying host keys when connecting to a previously-known SSH server. Th
This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An attacker in a privileged network position may be able to intercept SSH traffic from the “Run script over SSH” action.
nvd
CVE-2018-4433MEDIUMCVSS 5.5fixed in 12.02020-10-27
CVE-2018-4433 [MEDIUM] CVE-2018-4433: A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojav
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, watchOS 5, iOS 12, tvOS 12, macOS Mojave 10.14. A malicious application may be able to modify protected parts of the file system.
nvd
CVE-2019-8850MEDIUMCVSS 5.5fixed in 13.12020-10-27
CVE-2019-8850 [MEDIUM] CWE-125 CVE-2019-8850: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13.1 and iPadOS 13.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6. Processing a maliciously crafted audio file may disclose restricted memory.
nvd
CVE-2019-8668MEDIUMCVSS 5.5fixed in 12.42020-10-27
CVE-2019-8668 [MEDIUM] CWE-20 CVE-2019-8668: A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, t
A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2019-8528MEDIUMCVSS 6.7fixed in 12.22020-10-27
CVE-2019-8528 [MEDIUM] CWE-416 CVE-2019-8528: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8827MEDIUMCVSS 4.3fixed in 13.22020-10-27
CVE-2019-8827 [MEDIUM] CVE-2019-8827: The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading
The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a
nvd