cbcvebase.

Apple iOS vulnerabilities

4,134 known vulnerabilities affecting apple/iphone_os.

Total CVEs
4,134
CISA KEV
92
actively exploited
Public exploits
276
Exploited in wild
141
Severity breakdown
CRITICAL340HIGH1687MEDIUM1818LOW289

Vulnerabilities

Page 97 of 207
CVE-2019-8631P3HIGHCVSS 7.5fixed in 12.32020-10-27
CVE-2019-8631 [HIGH] CVE-2019-8631: A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.1 A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3. Users removed from an iMessage conversation may still be able to alter state.
nvd
CVE-2022-42796P3HIGHCVSS 7.8fixed in 15.72022-11-01
CVE-2022-42796 [HIGH] CWE-269 CVE-2022-42796: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be able to gain elevated privileges.
nvd
CVE-2017-13874P3HIGHCVSS 7.5fixed in 11.22017-12-25
CVE-2017-13874 [HIGH] CVE-2017-13874: An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves t An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "Mail" component. It might allow remote attackers to bypass an intended encryption protection mechanism by leveraging incorrect S/MIME certificate selection.
nvd
CVE-2024-44277P3HIGHCVSS 7.8fixed in 18.12024-10-28
CVE-2024-44277 [HIGH] CWE-787 CVE-2024-44277: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2023-32425P3HIGHCVSS 7.8fixed in 16.52023-09-06
CVE-2023-32425 [HIGH] CVE-2023-32425: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to gain elevated privileges.
nvd
CVE-2025-43407P3HIGHCVSS 7.8fixed in 26.12025-11-04
CVE-2025-43407 [HIGH] CWE-284 CVE-2025-43407: This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18 This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. An app may be able to break out of its sandbox.
nvd
CVE-2021-30874P3HIGHCVSS 7.5fixed in 15.02021-08-24
CVE-2021-30874 [HIGH] CWE-862 CVE-2021-30874: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 a An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.
nvd
CVE-2018-4436P3HIGHCVSS 7.5fixed in 12.1.12019-04-03
CVE-2018-4436 [HIGH] CWE-295 CVE-2018-4436: A certificate validation issue existed in configuration profiles. This was addressed with additional A certificate validation issue existed in configuration profiles. This was addressed with additional checks. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2.
nvd
CVE-2018-4274P3HIGHCVSS 7.5fixed in 11.4.12019-04-03
CVE-2018-4274 [HIGH] CWE-20 CVE-2018-4274: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.
nvd
CVE-2022-32927P3HIGHCVSS 7.5fixed in 15.7.1v16.02022-11-01
CVE-2022-32927 [HIGH] CWE-400 CVE-2022-32927: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining a malicious Wi-Fi network may result in a denial-of-service of the Settings app.
nvd
CVE-2017-2380P3HIGHCVSS 7.5≤ 10.2.12017-04-02
CVE-2017-2380 [HIGH] CWE-326 CVE-2017-2380: An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the Simple Certificate Enrollment Protocol (SCEP) implementation in the "Profiles" component. It allows remote attackers to bypass cryptographic protection mechanisms by leveraging DES support.
nvd
CVE-2024-27874P3HIGHCVSS 7.5fixed in 18.02024-09-17
CVE-2024-27874 [HIGH] CWE-400 CVE-2024-27874: This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2021-30997P3HIGHCVSS 7.5fixed in 15.22021-08-24
CVE-2021-30997 [HIGH] CWE-312 CVE-2021-30997: A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatic A S/MIME issue existed in the handling of encrypted email. This issue was addressed by not automatically loading some MIME parts. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker may be able to recover plaintext contents of an S/MIME-encrypted e-mail.
nvd
CVE-2015-1088P3MEDIUMCVSS 6.8≤ 8.22015-04-10
CVE-2015-1088 [MEDIUM] CWE-20 CVE-2015-1088: CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which a CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code via a crafted web site.
nvd
CVE-2024-54551P3HIGHCVSS 7.5fixed in 17.62025-03-21
CVE-2024-54551 [HIGH] CWE-119 CVE-2024-54551: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content may lead to a denial-of-service.
nvd
CVE-2019-14899P3HIGHCVSS 7.4fixed in 13.62019-12-11
CVE-2019-14899 [HIGH] CWE-300 CVE-2019-14899: A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a mal A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to in
nvd
CVE-2020-9903P3HIGHCVSS 7.5fixed in 13.62020-10-16
CVE-2020-9903 [HIGH] CWE-346 CVE-2020-9903: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. A malicious attacker may cause Safari to suggest a password for the wrong domain.
nvd
CVE-2022-46716P3HIGHCVSS 7.5fixed in 16.22023-04-10
CVE-2022-46716 [HIGH] CVE-2022-46716: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2. Private Relay functionality did not match system settings
nvd
CVE-2026-28991P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28991 [HIGH] CWE-125 CVE-2026-28991: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
nvd
CVE-2025-31219P3HIGHCVSS 7.1fixed in 18.52025-05-12
CVE-2025-31219 [HIGH] CWE-119 CVE-2025-31219: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
Apple iOS vulnerabilities | cvebase