Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 28 of 83
CVE-2026-28904P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28904 [HIGH] CWE-119 CVE-2026-28904: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28953P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28953 [HIGH] CWE-119 CVE-2026-28953: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2023-42875P3HIGHCVSS 7.3fixed in 17.0≥ unspecified, < 172025-04-11
CVE-2023-42875 [HIGH] CWE-94 CVE-2023-42875: Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadO
Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.
nvdapple
CVE-2016-1724P3HIGHCVSS 8.8fixed in 9.0.32016-02-01
CVE-2016-1724 [HIGH] CWE-119 CVE-2016-1724: WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote
WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.
nvdapple
CVE-2018-4145P3HIGHCVSS 8.8fixed in 11.12019-04-03
CVE-2018-4145 [HIGH] CWE-119 CVE-2018-4145: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4.
nvdapple
CVE-2018-4272P3HIGHCVSS 8.8fixed in 11.1.22019-04-03
CVE-2018-4272 [HIGH] CWE-119 CVE-2018-4272: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4264P3HIGHCVSS 8.8fixed in 11.1.22019-04-03
CVE-2018-4264 [HIGH] CWE-119 CVE-2018-4264: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2016-4584P3HIGHCVSS 8.8fixed in 9.1.22016-07-22
CVE-2016-4584 [HIGH] CWE-119 CVE-2016-4584: The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS befo
The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2018-4372P3HIGHCVSS 8.8fixed in 12.0.12019-04-03
CVE-2018-4372 [HIGH] CWE-119 CVE-2018-4372: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2016-4611P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4611 [HIGH] CWE-119 CVE-2016-4611: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2017-2506P3HIGHCVSS 8.8≤ 10.12017-05-22
CVE-2017-2506 [HIGH] CWE-119 CVE-2017-2506: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
nvdapple
CVE-2018-4378P3HIGHCVSS 8.8fixed in 12.0.12019-04-03
CVE-2018-4378 [HIGH] CWE-119 CVE-2018-4378: A memory corruption issue was addressed with improved validation. This issue affected versions prior
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2010-1783P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1783 [CRITICAL] CWE-119 CVE-2010-1783: WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on M
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; does not properly handle dynamic modification of a text node, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML d
nvd
CVE-2011-0216P3CRITICALCVSS 9.3≤ 5.0.5v1.0+54 more2011-07-21
CVE-2011-0216 [CRITICAL] CWE-189 CVE-2011-0216: Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary
Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.
nvd
CVE-2022-32892P3HIGHCVSS 8.6fixed in 16.02022-11-01
CVE-2022-32892 [HIGH] CVE-2022-32892: An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iO
An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2004-1121P4MEDIUMCVSS 5.0PoCv1.0v1.1+4 more2004-11-01
CVE-2004-1121 [MEDIUM] CVE-2004-1121: Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar
Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.
nvd
CVE-2008-2306P3CRITICALCVSS 9.3≤ 3.1.1v3.0+5 more2008-06-23
CVE-2008-2306 [CRITICAL] CWE-264 CVE-2008-2306: Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRIS
Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.
nvd
CVE-2026-64719P3HIGHCVSS 8.1fixed in 26.62026-07-27
CVE-2026-64719 [HIGH] CWE-125 CVE-2026-64719: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2010-1402P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1402 [CRITICAL] CWE-399 CVE-2010-1402: Double free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Win
Double free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to an event listener in an SVG document, related to duplicate event listeners, a timer, and a
nvd
CVE-2010-1749P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1749 [CRITICAL] CWE-399 CVE-2010-1749: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Cascading Style Sheets (CSS) run-in property and multiple invocations of a destructo
nvd