Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 19 of 84
CVE-2026-28847P3HIGHCVSS 8.8fixed in 26.52026-05-11
CVE-2026-28847 [HIGH] CWE-119 CVE-2026-28847: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-64757P3HIGHCVSS 8.8fixed in 26.62026-07-27
CVE-2026-64757 [HIGH] CWE-119 CVE-2026-64757: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-28947P3HIGHCVSS 8.8fixed in 26.52026-05-11
CVE-2026-28947 [HIGH] CWE-416 CVE-2026-28947: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2009-0946P3HIGHCVSS 7.5v4.02009-04-17
CVE-2009-0946 [HIGH] CWE-190 CVE-2009-0946: Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
nvd
CVE-2016-1723P3HIGHCVSS 8.8≤ 9.0.22016-02-01
CVE-2016-1723 [HIGH] CWE-119 CVE-2016-1723: WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execut
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1725 and CVE-2016-1726.
nvdapple
CVE-2021-30984P3HIGHCVSS 7.5fixed in 15.22021-08-24
CVE-2021-30984 [HIGH] CWE-362 CVE-2021-30984: A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2016-1778P3HIGHCVSS 8.8≤ 9.0.32016-03-24
CVE-2016-1778 [HIGH] CWE-399 CVE-2016-1778: WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary co
WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2018-4190P3HIGHCVSS 8.8fixed in 11.1.12018-06-08
CVE-2018-4190 [HIGH] CWE-522 CVE-2018-4190: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive credential information that is tra
nvdapple
CVE-2025-24264P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24264 [CRITICAL] CWE-400 CVE-2025-24264: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43343P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43343 [CRITICAL] CWE-119 CVE-2025-43343: The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-43526P3CRITICALCVSS 9.8fixed in 26.22025-12-17
CVE-2025-43526 [CRITICAL] CWE-601 CVE-2025-43526: This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tah
This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
nvdapple
CVE-2009-1712P3CRITICALCVSS 9.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1712 [CRITICAL] CWE-94 CVE-2009-1712: WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allow
WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.
nvd
CVE-2009-2419P4MEDIUMCVSS 4.3PoCv4.0v4.0.12009-07-09
CVE-2009-2419 [MEDIUM] CWE-399 CVE-2009-2419: Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safa
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these detai
nvd
CVE-2017-13884P3HIGHCVSS 8.8fixed in 11.0.22018-04-03
CVE-2017-13884 [HIGH] CWE-119 CVE-2017-13884: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary
nvdapple
CVE-2017-7165P3HIGHCVSS 8.8fixed in 11.0.22018-04-03
CVE-2017-7165 [HIGH] CWE-119 CVE-2017-7165: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary c
nvdapple
CVE-2018-4201P3HIGHCVSS 8.8fixed in 11.1.12018-06-08
CVE-2018-4201 [HIGH] CWE-119 CVE-2018-4201: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary
nvdapple
CVE-2016-4728P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4728 [HIGH] CWE-20 CVE-2016-4728: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote attackers to execute arbitrary code via a crafted web site.
nvdapple
CVE-2017-2463P3HIGHCVSS 8.8fixed in 10.12017-04-02
CVE-2017-2463 [HIGH] CWE-416 CVE-2017-2463: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. iTunes before 12.6 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (me
nvdapple
CVE-2018-4122P3HIGHCVSS 8.8fixed in 11.12018-04-03
CVE-2018-4122 [HIGH] CWE-119 CVE-2018-4122: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvdapple
CVE-2018-4129P3HIGHCVSS 8.8fixed in 11.12018-04-03
CVE-2018-4129 [HIGH] CWE-119 CVE-2018-4129: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvdapple