Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 27 of 84
CVE-2016-4768P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4768 [HIGH] CVE-2016-4768: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4767.
nvdapple
CVE-2016-4759P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4759 [HIGH] CWE-119 CVE-2016-4759: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4765, CVE-2016-4766, CVE-2016-4767, and CVE-2016-4768.
nvdapple
CVE-2016-4767P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4767 [HIGH] CVE-2016-4767: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.
nvdapple
CVE-2016-4766P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4766 [HIGH] CVE-2016-4766: WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4767, and CVE-2016-4768.
nvdapple
CVE-2016-1855P3HIGHCVSS 8.8fixed in 9.1.12016-05-20
CVE-2016-1855 [HIGH] CVE-2016-1855: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1856, and CVE-2016-1857.
nvdapple
CVE-2019-8503P3HIGHCVSS 8.8fixed in 12.1≥ unspecified, < Safari 12.12019-12-18
CVE-2019-8503 [HIGH] CWE-20 CVE-2019-8503: A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Sa
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious website may be able to execute scripts in the context of another website.
nvdapple
CVE-2010-1789P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1789 [CRITICAL] CWE-119 CVE-2010-1789: Heap-based buffer overflow in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and
Heap-based buffer overflow in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a JavaScript string object.
nvd
CVE-2017-7012P3HIGHCVSS 8.8fixed in 10.1.22017-07-20
CVE-2017-7012 [HIGH] CWE-119 CVE-2017-7012: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
nvdapple
CVE-2016-4764P3HIGHCVSS 8.8≤ 9.1.32017-02-20
CVE-2016-4764 [HIGH] CWE-119 CVE-2016-4764: An issue was discovered in certain Apple products. iOS before 10 is affected. Safari before 10 is af
An issue was discovered in certain Apple products. iOS before 10 is affected. Safari before 10 is affected. iTunes before 12.5.1 is affected. tvOS before 10 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web
nvdapple
CVE-2017-2544P3HIGHCVSS 8.8≤ 10.12017-05-22
CVE-2017-2544 [HIGH] CWE-119 CVE-2017-2544: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2017-2526P3HIGHCVSS 8.8≤ 10.12017-05-22
CVE-2017-2526 [HIGH] CWE-119 CVE-2017-2526: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2026-43670P3HIGHCVSS 8.8fixed in 26.52026-08-25
CVE-2026-43670 [HIGH] CWE-693 CVE-2026-43670: A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. T
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
nvd
CVE-2009-1724P4MEDIUMCVSS 4.3PoC≤ 4.0.1v2.0+25 more2009-07-09
CVE-2009-1724 [MEDIUM] CWE-79 CVE-2009-1724: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone O
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.
nvd
CVE-2009-0162P4MEDIUMCVSS 4.3PoC≤ 3.2.2v0.8+44 more2009-05-13
CVE-2009-0162 [MEDIUM] CWE-79 CVE-2009-0162: Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.
nvd
CVE-2021-30954P3HIGHCVSS 7.8fixed in 15.22021-08-24
CVE-2021-30954 [HIGH] CWE-843 CVE-2021-30954: A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2026-64719P3HIGHCVSS 8.1fixed in 26.62026-07-27
CVE-2026-64719 [HIGH] CWE-125 CVE-2026-64719: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-31223P3HIGHCVSS 8.0fixed in 18.52025-05-12
CVE-2025-31223 [HIGH] CWE-119 CVE-2025-31223: The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2018-4147P3CRITICALCVSS 9.8fixed in 11.0.32019-01-11
CVE-2018-4147 [CRITICAL] CWE-119 CVE-2018-4147: In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS be
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.
nvdapple
CVE-2026-28904P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28904 [HIGH] CWE-119 CVE-2026-28904: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28953P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28953 [HIGH] CWE-119 CVE-2026-28953: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd