Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 29 of 83
CVE-2009-1698P3CRITICALCVSS 9.3≤ 3.2.2v2.0+22 more2009-06-10
CVE-2009-1698 [CRITICAL] CWE-94 CVE-2009-1698: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and a
nvd
CVE-2008-2540P3CRITICALCVSS 9.3fixed in 3.1.22008-06-03
CVE-2008-2540 [CRITICAL] CVE-2008-2540: Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading a
Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by l
nvd
CVE-2025-43376P3HIGHCVSS 7.5fixed in 26.0fixed in 262025-11-04
CVE-2025-43376 [HIGH] CVE-2025-43376: A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18
A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
nvdapple
CVE-2026-28905P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28905 [HIGH] CWE-119 CVE-2026-28905: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28883P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28883 [HIGH] CWE-416 CVE-2026-28883: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43658P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-43658 [HIGH] CWE-119 CVE-2026-43658: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-30466P3CRITICALCVSS 9.8fixed in 18.42025-05-29
CVE-2025-30466 [CRITICAL] CWE-346 CVE-2025-30466: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.
nvdapple
CVE-2016-4731P3HIGHCVSS 8.8≤ 9.1.32016-09-25
CVE-2016-4731 [HIGH] CVE-2016-4731: WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code
WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4729.
nvdapple
CVE-2016-4729P3HIGHCVSS 8.8≤ 9.1.32016-09-25
CVE-2016-4729 [HIGH] CWE-119 CVE-2016-4729: WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code
WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4731.
nvdapple
CVE-2018-4262P3HIGHCVSS 8.8fixed in 11.1.22019-01-11
CVE-2018-4262 [HIGH] CWE-119 CVE-2018-4262: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
nvdapple
CVE-2018-4261P3HIGHCVSS 8.8fixed in 11.1.22019-04-03
CVE-2018-4261 [HIGH] CWE-119 CVE-2018-4261: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4265P3HIGHCVSS 8.8fixed in 11.1.22019-04-03
CVE-2018-4265 [HIGH] CWE-119 CVE-2018-4265: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4263P3HIGHCVSS 8.8fixed in 11.1.22019-04-03
CVE-2018-4263 [HIGH] CWE-119 CVE-2018-4263: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2018-4267P3HIGHCVSS 8.8fixed in 11.1.22019-04-03
CVE-2018-4267 [HIGH] CWE-119 CVE-2018-4267: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2010-1399P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1399 [CRITICAL] CWE-119 CVE-2010-1399: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during a selection change on a form input element, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.
nvd
CVE-2010-1415P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1415 [CRITICAL] CWE-94 CVE-2010-1415: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle libxml contexts, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to an "API abuse issue."
nvd
CVE-2011-3438P3HIGHCVSS 8.8v5.0.62017-04-24
CVE-2011-3438 [HIGH] CWE-119 CVE-2011-3438: WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash
WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution.
nvd
CVE-2024-44206P3CRITICALCVSS 9.3fixed in 17.62024-10-24
CVE-2024-44206 [CRITICAL] CVE-2024-44206: An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in
An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A user may be able to bypass some web content restrictions.
nvdapple
CVE-2018-4373P3HIGHCVSS 8.8fixed in 12.0.12019-04-03
CVE-2018-4373 [HIGH] CWE-119 CVE-2018-4373: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2018-4284P3HIGHCVSS 8.8fixed in 11.1.22019-04-03
CVE-2018-4284 [HIGH] CWE-704 CVE-2018-4284: A type confusion issue was addressed with improved memory handling. This issue affected versions pri
A type confusion issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple