Apple iOS vulnerabilities
4,134 known vulnerabilities affecting apple/iphone_os.
Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289
Vulnerabilities
Page 96 of 207
CVE-2015-5942P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5942 [MEDIUM] CVE-2015-5942: FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote atta
FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5927.
nvd
CVE-2018-4465P3HIGHCVSS 7.8fixed in 12.1.12019-04-03
CVE-2018-4465 [HIGH] CWE-119 CVE-2018-4465: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2022-32837P3HIGHCVSS 7.8fixed in 15.62022-08-24
CVE-2022-32837 [HIGH] CWE-787 CVE-2022-32837: This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, tvOS 15.6
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2015-5927P3MEDIUMCVSS 6.8≤ 9.0.22015-10-23
CVE-2015-5927 [MEDIUM] CWE-119 CVE-2015-5927: FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote atta
FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5942.
nvd
CVE-2020-9825P3HIGHCVSS 7.8fixed in 13.52020-06-09
CVE-2020-9825 [HIGH] CVE-2020-9825: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.5
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2015-5829P3MEDIUMCVSS 6.8≤ 8.4.12015-09-18
CVE-2015-5829 [MEDIUM] CWE-119 CVE-2015-5829: Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cau
Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file.
nvd
CVE-2015-3719P3MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3719 [MEDIUM] CVE-2015-3719: TrueTypeScaler in FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers
TrueTypeScaler in FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3694.
nvd
CVE-2015-3694P3MEDIUMCVSS 6.8≤ 8.1.32015-07-03
CVE-2015-3694 [MEDIUM] CWE-119 CVE-2015-3694: FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitr
FontParser in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3719.
nvd
CVE-2015-1098P3HIGHCVSS 7.3fixed in 8.32015-04-10
CVE-2015-1098 [HIGH] CWE-119 CVE-2015-1098: iWork in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbit
iWork in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file.
nvd
CVE-2016-4653P3HIGHCVSS 7.8fixed in 9.3.32016-07-22
CVE-2016-4653 [HIGH] CVE-2016-4653: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4582.
nvd
CVE-2015-3723P3MEDIUMCVSS 6.8≤ 8.32015-07-03
CVE-2015-3723 [MEDIUM] CWE-119 CVE-2015-3723: CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a de
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724.
nvd
CVE-2023-38603P3HIGHCVSS 7.5fixed in 15.7.8≥ 16.0, < 16.62023-07-27
CVE-2023-38603 [HIGH] CVE-2023-38603: The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A remote user may be able to cause a denial-of-service.
nvd
CVE-2019-8633P3HIGHCVSS 7.5fixed in 12.32020-10-27
CVE-2019-8633 [HIGH] CWE-20 CVE-2019-8633: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3, watchOS 5.3. An application may be able to read restricted memory.
nvd
CVE-2021-30729P3HIGHCVSS 7.5fixed in 14.62021-09-08
CVE-2021-30729 [HIGH] CVE-2021-30729: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.6 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.6 and iPadOS 14.6. A device may accept invalid activation results.
nvd
CVE-2016-4582P3HIGHCVSS 7.8fixed in 9.3.32016-07-22
CVE-2016-4582 [HIGH] CVE-2016-4582: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4653.
nvd
CVE-2022-22653P3HIGHCVSS 7.5fixed in 15.42022-03-18
CVE-2022-22653 [HIGH] CVE-2022-22653: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4. A malicious website may be able to access information about the user and their devices.
nvd
CVE-2016-1832P3HIGHCVSS 7.8fixed in 9.3.22016-05-20
CVE-2016-1832 [HIGH] CWE-119 CVE-2016-1832: libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 all
libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2022-22618P3HIGHCVSS 7.8fixed in 15.42022-03-18
CVE-2022-22618 [HIGH] CVE-2022-22618: This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and iPad
This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. A user may be able to bypass the Emergency SOS passcode prompt.
nvd
CVE-2016-1722P3HIGHCVSS 7.8fixed in 9.2.12016-02-01
CVE-2016-1722 [HIGH] CWE-119 CVE-2016-1722: syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to g
syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-7630P3CRITICALCVSS 9.8≤ 10.1.12017-02-20
CVE-2016-7630 [CRITICAL] CWE-254 CVE-2016-7630: An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves t
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebSheet" component, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
nvd