Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 21 of 83
CVE-2019-8556P3HIGHCVSS 8.8fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-8556 [HIGH] CWE-416 CVE-2019-8556: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2020-3825P3HIGHCVSS 8.8fixed in 3.0.5≥ unspecified, < Safari 13.0.52020-02-27
CVE-2020-3825 [HIGH] CWE-787 CVE-2020-3825: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2025-31204P3HIGHCVSS 8.8fixed in 18.52025-05-12
CVE-2025-31204 [HIGH] CWE-119 CVE-2025-31204: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2025-24189P3HIGHCVSS 8.8fixed in 18.32025-05-19
CVE-2025-24189 [HIGH] CWE-119 CVE-2025-24189: The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2016-4734P3CRITICALCVSS 9.6fixed in 10.02016-09-25
CVE-2016-4734 [CRITICAL] CVE-2016-4734: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4735.
nvdapple
CVE-2021-30846P3HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-19
CVE-2021-30846 [HIGH] CWE-787 CVE-2021-30846: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2016-1723P3HIGHCVSS 8.8≤ 9.0.22016-02-01
CVE-2016-1723 [HIGH] CWE-119 CVE-2016-1723: WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execut
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1725 and CVE-2016-1726.
nvdapple
CVE-2016-1725P3HIGHCVSS 8.8≤ 9.0.22016-02-01
CVE-2016-1725 [HIGH] CVE-2016-1725: WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execut
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1726.
nvdapple
CVE-2016-1726P3HIGHCVSS 8.8≤ 9.0.22016-02-01
CVE-2016-1726 [HIGH] CVE-2016-1726: WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execut
WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1725.
nvdapple
CVE-2016-1727P3HIGHCVSS 8.8fixed in 9.0.32016-02-01
CVE-2016-1727 [HIGH] CVE-2016-1727: WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote
WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1724.
nvdapple
CVE-2021-30984P3HIGHCVSS 7.5fixed in 15.22021-08-24
CVE-2021-30984 [HIGH] CWE-362 CVE-2021-30984: A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2010-1383P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2010-1383 [CRITICAL] CWE-255 CVE-2010-1383: CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary cod
CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.
nvd
CVE-2025-43342P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43342 [CRITICAL] CWE-20 CVE-2025-43342: A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 a
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2016-1783P3HIGHCVSS 8.8fixed in 9.12016-03-24
CVE-2016-1783 [HIGH] CWE-119 CVE-2016-1783: WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to ex
WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2021-21779P3HIGHCVSS 8.8v14.1.12021-05-24
CVE-2021-21779 [HIGH] CVE-2021-21779: Safari 14.1.1
Apple Security Update: About the security content of Safari 14.1.1
Product: Safari
Version: 14.1.1
CVE: CVE-2021-21779
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2017-13885P3HIGHCVSS 8.8fixed in 11.0.22018-04-03
CVE-2017-13885 [HIGH] CWE-119 CVE-2017-13885: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of servi
nvdapple
CVE-2017-7160P3HIGHCVSS 8.8fixed in 11.0.22017-12-27
CVE-2017-7160 [HIGH] CWE-119 CVE-2017-7160: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple
CVE-2017-7157P3HIGHCVSS 8.8fixed in 11.0.22017-12-27
CVE-2017-7157 [HIGH] CWE-119 CVE-2017-7157: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple
CVE-2017-7156P3HIGHCVSS 8.8fixed in 11.0.22017-12-27
CVE-2017-7156 [HIGH] CWE-119 CVE-2017-7156: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple
CVE-2017-13856P3HIGHCVSS 8.8fixed in 11.0.22017-12-25
CVE-2017-13856 [HIGH] CWE-119 CVE-2017-13856: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of servi
nvdapple