Apple Safari vulnerabilities
1,613 known vulnerabilities affecting apple/safari.
Total CVEs
1,613
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH615MEDIUM766LOW20UNKNOWN1
Vulnerabilities
Page 10 of 81
CVE-2024-23271MEDIUMCVSS 6.5fixed in 17.32024-04-24
CVE-2024-23271 [MEDIUM] CWE-284 CVE-2024-23271: A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and i
A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
nvdapple
CVE-2023-42950HIGHCVSS 8.8fixed in 17.2≥ unspecified, < 17.22024-03-28
CVE-2023-42950 [HIGH] CWE-416 CVE-2023-42950: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42956MEDIUMCVSS 6.5fixed in 17.2≥ unspecified, < 17.22024-03-28
CVE-2023-42956 [MEDIUM] CVE-2023-42956: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2024-23280MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23280 [MEDIUM] CWE-74 CVE-2024-23280: An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 1
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2024-23273MEDIUMCVSS 4.3fixed in 17.42024-03-08
CVE-2024-23273 [MEDIUM] CWE-295 CVE-2024-23273: This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.
nvdapple
CVE-2024-23284MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23284 [MEDIUM] CWE-693 CVE-2024-23284: A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvdapple
CVE-2024-23263MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23263 [MEDIUM] CWE-20 CVE-2024-23263: A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvdapple
CVE-2024-23254MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23254 [MEDIUM] CVE-2024-23254: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
nvdapple
CVE-2023-42843MEDIUMCVSS 4.3fixed in 17.1≥ unspecified, < 17.12024-02-21
CVE-2023-42843 [MEDIUM] CWE-290 CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2024-1580HIGHCVSS 8.8fixed in 17.4.12024-02-19
CVE-2024-1580 [HIGH] CWE-190 CVE-2024-1580: An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size.
An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
nvdapple
CVE-2024-23222HIGHCVSS 8.8KEVfixed in 17.32024-01-23
CVE-2024-23222 [HIGH] CWE-843 CVE-2024-23222: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 1
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-23213HIGHCVSS 8.8fixed in 17.32024-01-23
CVE-2024-23213 [HIGH] CWE-119 CVE-2024-23213: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2024-23206MEDIUMCVSS 6.5fixed in 17.32024-01-23
CVE-2024-23206 [MEDIUM] CWE-200 CVE-2024-23206: An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3,
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2024-23211LOWCVSS 3.3fixed in 17.32024-01-23
CVE-2024-23211 [LOW] CWE-359 CVE-2024-23211: A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Saf
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A user's private browsing activity may be visible in Settings.
nvdapple
CVE-2023-40414CRITICALCVSS 9.8fixed in 17.0≥ unspecified, < 172024-01-10
CVE-2023-40414 [CRITICAL] CWE-416 CVE-2023-40414: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, tvOS 17, macOS Sonoma 14, Safari 17. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42866HIGHCVSS 8.8fixed in 16.6≥ unspecified, < 16.62024-01-10
CVE-2023-42866 [HIGH] CVE-2023-42866: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iO
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42833HIGHCVSS 8.8fixed in 17.0≥ unspecified, < 172024-01-10
CVE-2023-42833 [HIGH] CWE-94 CVE-2023-42833: A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safa
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2023-40385MEDIUMCVSS 6.5fixed in 17.0≥ unspecified, < 172024-01-10
CVE-2023-40385 [MEDIUM] CWE-200 CVE-2023-40385: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Sa
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
nvdapple
CVE-2023-42872MEDIUMCVSS 5.5fixed in 17.02024-01-10
CVE-2023-42872 [MEDIUM] CVE-2023-42872: The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14,
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to access sensitive user data.
nvd
CVE-2023-42890HIGHCVSS 8.8fixed in 17.2≥ unspecified, < 17.22023-12-12
CVE-2023-42890 [HIGH] CWE-94 CVE-2023-42890: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Son
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.
nvdapple