cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 89 of 207
CVE-2024-40856P3HIGHCVSS 7.5fixed in 18.02024-09-17
CVE-2024-40856 [HIGH] CVE-2024-40856: An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18 An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18. An attacker may be able to force a device to disconnect from a secure network.
nvd
CVE-2025-24095P3HIGHCVSS 7.6fixed in 18.42025-03-31
CVE-2025-24095 [HIGH] CWE-288 CVE-2025-24095: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4. An app may be able to bypass Privacy preferences.
nvd
CVE-2008-4211P3CRITICALCVSS 10.0v1.0.0v1.0.1+11 more2008-10-10
CVE-2008-4211 [CRITICAL] CWE-189 CVE-2008-4211: Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iP Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory acc
nvd
CVE-2025-43541P4MEDIUMCVSS 4.3fixed in 18.7.3≥ 26.0, < 26.22025-12-17
CVE-2025-43541 [MEDIUM] CWE-843 CVE-2025-43541: A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26. A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2024-44227P3HIGHCVSS 7.5fixed in 18.02025-03-10
CVE-2024-44227 [HIGH] CWE-400 CVE-2024-44227: The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-28986P3HIGHCVSS 7.5fixed in 18.7.9≥ 26.0, < 26.52026-05-11
CVE-2026-28986 [HIGH] CWE-362 CVE-2026-28986: A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPa A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
nvd
CVE-2021-30662P3HIGHCVSS 7.3fixed in 14.52021-09-08
CVE-2021-30662 [HIGH] CVE-2021-30662: This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. Proc This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.
nvd
CVE-2015-1157P3HIGHCVSS 7.8v8.0v8.0.1+6 more2015-05-28
CVE-2015-1157 [HIGH] CWE-17 CVE-2015-1157: CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot a CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.
nvd
CVE-2009-1701P3CRITICALCVSS 9.3v1.0.0v1.0.1+15 more2009-06-10
CVE-2009-1701 [CRITICAL] CWE-399 CVE-2009-1701: Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4 Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML contai
nvd
CVE-2025-24209P3HIGHCVSS 7.0fixed in 18.42025-03-31
CVE-2025-24209 [HIGH] CWE-120 CVE-2025-24209: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 1 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2014-4377P3MEDIUMCVSS 6.8≤ 7.1.2v7.0+8 more2014-09-18
CVE-2014-4377 [MEDIUM] CWE-189 CVE-2014-4377: Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
nvd
CVE-2015-5776P3HIGHCVSS 7.5≤ 8.42015-08-17
CVE-2015-5776 [HIGH] CWE-119 CVE-2015-5776: Libinfo in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitra Libinfo in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by leveraging use of an AF_INET6 socket.
nvd
CVE-2014-4484P3HIGHCVSS 7.5≤ 8.1.22015-01-30
CVE-2014-4484 [HIGH] CWE-19 CVE-2014-4484: FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows re FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .dfont file.
nvd
CVE-2021-23841P3MEDIUMCVSS 5.9fixed in 14.62021-02-16
CVE-2021-23841 [MEDIUM] CWE-476 CVE-2021-23841: The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This ma
nvd
CVE-2018-4275P3HIGHCVSS 8.6fixed in 11.4.12019-04-03
CVE-2018-4275 [HIGH] CWE-119 CVE-2018-4275: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1.
nvd
CVE-2018-4140P3HIGHCVSS 7.5fixed in 11.32018-04-03
CVE-2018-4140 [HIGH] CWE-476 CVE-2018-4140: An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 11.3 is affected. The issue involves the "Telephony" component. It allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a Class 0 SMS message.
nvd
CVE-2022-42844P3HIGHCVSS 8.6fixed in 16.22022-12-15
CVE-2022-42844 [HIGH] CWE-119 CVE-2022-42844: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox.
nvd
CVE-2018-4327P3HIGHCVSS 7.8fixed in 11.4.12019-04-03
CVE-2018-4327 [HIGH] CWE-119 CVE-2018-4327: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1.
nvd
CVE-2023-32437P3HIGHCVSS 8.6fixed in 16.62023-07-27
CVE-2023-32437 [HIGH] CVE-2023-32437: The issue was addressed with improvements to the file handling protocol. This issue is fixed in iOS The issue was addressed with improvements to the file handling protocol. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be able to break out of its sandbox.
nvd
CVE-2017-2461P3HIGHCVSS 7.5≤ 10.2.12017-04-02
CVE-2017-2461 [HIGH] CWE-20 CVE-2017-2461: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
nvd
Apple iOS vulnerabilities | cvebase