Apple Safari vulnerabilities

1,546 known vulnerabilities affecting apple/safari.

Total CVEs
1,546
CISA KEV
27
actively exploited
Public exploits
145
Exploited in wild
21
Severity breakdown
CRITICAL211HIGH575MEDIUM741LOW19

Vulnerabilities

Page 11 of 78
CVE-2023-32439HIGHCVSS 8.8KEVfixed in 16.5.1≥ unspecified, < 16.52023-06-23
CVE-2023-32439 [HIGH] CWE-843 CVE-2023-32439: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPa A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
cvelistv5nvd
CVE-2023-32435HIGHCVSS 8.8KEVfixed in 16.4≥ unspecified, < 16.42023-06-23
CVE-2023-32435 [HIGH] CWE-787 CVE-2023-32435: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released
cvelistv5nvd
CVE-2023-28204MEDIUMCVSS 6.5KEVfixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-28204 [MEDIUM] CWE-125 CVE-2023-28204: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
cvelistv5nvd
CVE-2023-32402MEDIUMCVSS 6.5fixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32402 [MEDIUM] CWE-125 CVE-2023-32402: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
cvelistv5nvd
CVE-2023-32423MEDIUMCVSS 6.5fixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32423 [MEDIUM] CWE-120 CVE-2023-32423: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
cvelistv5nvd
CVE-2023-28201CRITICALCVSS 9.8fixed in 16.4≥ unspecified, < 16.42023-05-08
CVE-2023-28201 [CRITICAL] CWE-362 CVE-2023-28201: This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary code execution.
cvelistv5nvd
CVE-2022-32885HIGHCVSS 8.8fixed in 15.62023-05-08
CVE-2022-32885 [HIGH] CWE-787 CVE-2022-32885: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 an A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution
nvd
CVE-2023-27932MEDIUMCVSS 5.5fixed in 16.4≥ unspecified, < 16.42023-05-08
CVE-2023-27932 [MEDIUM] CWE-346 CVE-2023-27932: This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
cvelistv5nvd
CVE-2023-27954MEDIUMCVSS 6.5fixed in 16.4≥ unspecified, < 16.42023-05-08
CVE-2023-27954 [MEDIUM] CWE-863 CVE-2023-27954: The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, S The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information.
cvelistv5nvd
CVE-2023-28205HIGHCVSS 8.8KEVfixed in 16.4.1≥ unspecified, < 16.42023-04-10
CVE-2023-28205 [HIGH] CWE-416 CVE-2023-28205: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
cvelistv5nvd
CVE-2023-23517HIGHCVSS 8.8fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23517 [HIGH] CWE-119 CVE-2023-23517: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2023-23518HIGHCVSS 8.8fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23518 [HIGH] CWE-787 CVE-2023-23518: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2023-23496HIGHCVSS 8.8fixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23496 [HIGH] CWE-94 CVE-2023-23496: The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3 The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
cvelistv5nvd
CVE-2022-42826HIGHCVSS 8.8fixed in 16.12023-02-27
CVE-2022-42826 [HIGH] CWE-416 CVE-2022-42826: A use after free issue was addressed with improved memory management. This issue is fixed in macOS V A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-23529HIGHCVSS 8.8KEVfixed in 16.3≥ unspecified, < 16.32023-02-27
CVE-2023-23529 [HIGH] CWE-843 CVE-2023-23529: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPa A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
cvelistv5nvd
CVE-2022-46705MEDIUMCVSS 4.3fixed in 16.22023-02-27
CVE-2022-46705 [MEDIUM] CVE-2022-46705: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2022-32891MEDIUMCVSS 6.1fixed in 16.0≥ unspecified, < 162023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
cvelistv5nvd
CVE-2022-32784MEDIUMCVSS 6.5fixed in 15.6≥ unspecified, < 15.62023-02-27
CVE-2022-32784 [MEDIUM] CWE-200 CVE-2022-32784: The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and iPadOS 15.6. Visiting a maliciously crafted website may leak sensitive data.
cvelistv5nvd
CVE-2022-42863HIGHCVSS 8.8fixed in 16.22022-12-15
CVE-2022-42863 [HIGH] CWE-787 CVE-2022-42863: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-46699HIGHCVSS 8.8fixed in 16.22022-12-15
CVE-2022-46699 [HIGH] CWE-787 CVE-2022-46699: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd