cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 92 of 207
CVE-2020-29619P3HIGHCVSS 7.8fixed in 14.32021-04-02
CVE-2020-29619 [HIGH] CWE-125 CVE-2020-29619: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3 An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.
nvd
CVE-2020-29614P3HIGHCVSS 7.8fixed in 14.32021-04-02
CVE-2020-29614 [HIGH] CWE-787 CVE-2020-29614: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted file may lead to heap corruption.
nvd
CVE-2020-29617P3HIGHCVSS 7.8fixed in 14.32021-04-02
CVE-2020-29617 [HIGH] CWE-125 CVE-2020-29617: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3 An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.
nvd
CVE-2017-7128P3CRITICALCVSS 9.8≤ 10.3.32017-10-23
CVE-2017-7128 [CRITICAL] CWE-119 CVE-2017-7128: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
nvd
CVE-2017-7130P3CRITICALCVSS 9.8≤ 10.3.32017-10-23
CVE-2017-7130 [CRITICAL] CWE-119 CVE-2017-7130: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
nvd
CVE-2017-7129P3CRITICALCVSS 9.8≤ 10.3.32017-10-23
CVE-2017-7129 [CRITICAL] CWE-119 CVE-2017-7129: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other i
nvd
CVE-2010-4494P3HIGHCVSS 7.5fixed in 4.3.02010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2019-8620P3HIGHCVSS 7.5fixed in 12.32019-12-18
CVE-2019-8620 [HIGH] CWE-200 CVE-2019-8620: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A device may be passively tracked by its WiFi MAC address.
nvd
CVE-2020-3913P3HIGHCVSS 7.8fixed in 13.42020-04-01
CVE-2020-3913 [HIGH] CVE-2020-3913: A permissions issue existed. This issue was addressed with improved permission validation. This issu A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, watchOS 6.2. A malicious application may be able to elevate privileges.
nvd
CVE-2016-7662P3HIGHCVSS 7.5≤ 10.1.12017-02-20
CVE-2016-7662 [HIGH] CWE-295 CVE-2016-7662: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows remote attackers to spoof certificates via unspecified vectors.
nvd
CVE-2019-8699P3HIGHCVSS 7.5fixed in 12.42019-12-18
CVE-2019-8699 [HIGH] CVE-2019-8699: A logic issue existed in the handling of answering phone calls. The issue was addressed with improve A logic issue existed in the handling of answering phone calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.4. The initiator of a phone call may be able to cause the recipient to answer a simultaneous Walkie-Talkie connection.
nvd
CVE-2020-9914P3HIGHCVSS 7.5fixed in 13.62020-10-16
CVE-2020-9914 [HIGH] CWE-20 CVE-2020-9914: An input validation issue existed in Bluetooth. This issue was addressed with improved input validat An input validation issue existed in Bluetooth. This issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An attacker in a privileged network position may be able to perform denial of service attack using malformed Bluetooth packets.
nvd
CVE-2021-30826P3HIGHCVSS 7.5fixed in 15.02021-10-19
CVE-2021-30826 [HIGH] CVE-2021-30826: A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. In certain situations, the baseband would fail to enable integrity and ciphering protection.
nvd
CVE-2019-8854P3HIGHCVSS 7.5fixed in 13.22020-10-27
CVE-2019-8854 [HIGH] CVE-2019-8854: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in mac A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. A device may be passively tracked by its Wi-Fi MAC address.
nvd
CVE-2016-4693P3HIGHCVSS 7.5≤ 10.1.12017-02-20
CVE-2016-4693 [HIGH] CWE-326 CVE-2016-4693: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which makes it easier for attackers to bypass cryptographic protection mechanisms by leveraging use of the 3DES cipher.
nvd
CVE-2016-1717P3HIGHCVSS 7.8fixed in 9.2.12016-02-01
CVE-2016-1717 [HIGH] CWE-119 CVE-2016-1717: The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allo The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2023-32396P3HIGHCVSS 7.8fixed in 17.02023-09-27
CVE-2023-32396 [HIGH] CVE-2023-32396: This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges.
nvd
CVE-2017-7080P3HIGHCVSS 7.5≤ 10.3.32017-10-23
CVE-2017-7080 [HIGH] CWE-295 CVE-2017-7080: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended certificate-trust restrictions via a revoked X.509 certificate.
nvd
CVE-2025-24173P3HIGHCVSS 7.8fixed in 18.42025-03-31
CVE-2025-24173 [HIGH] CWE-284 CVE-2025-24173: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvd
CVE-2017-13903P3HIGHCVSS 7.5fixed in 11.2.12017-12-25
CVE-2017-13903 [HIGH] CVE-2017-13903: An issue was discovered in certain Apple products. iOS before 11.2.1 is affected. tvOS before 11.2.1 An issue was discovered in certain Apple products. iOS before 11.2.1 is affected. tvOS before 11.2.1 is affected. The issue involves the "HomeKit" component. It allows remote attackers to modify the application state by leveraging incorrect message handling, as demonstrated by use of an Apple Watch to obtain an encryption key and unlock a door.
nvd
Apple iOS vulnerabilities | cvebase