Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 30 of 83
CVE-2010-1790P3CRITICALCVSS 9.3≤ 5.0v4.0+7 more2010-07-30
CVE-2010-1790 [CRITICAL] CVE-2010-1790: WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on M
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; does not properly handle just-in-time (JIT) compiled JavaScript stubs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to a
nvd
CVE-2009-1708P3CRITICALCVSS 9.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1708 [CRITICAL] CVE-2009-1708: Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, whi
Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary local help files, and execute arbitrary code or obtain sensitive information, via a crafted call.
nvd
CVE-2010-0045P3CRITICALCVSS 9.3≤ 4.0.4v4.0+3 more2010-03-15
CVE-2010-0045 [CRITICAL] CWE-20 CVE-2010-0045: Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows r
Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.
nvd
CVE-2008-5821P4MEDIUMCVSS 5.0PoCv3.22009-01-02
CVE-2008-5821 [MEDIUM] CWE-399 CVE-2008-5821: Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.
nvd
CVE-2025-24180P3HIGHCVSS 8.1fixed in 18.42025-03-31
CVE-2025-24180 [HIGH] CWE-601 CVE-2025-24180: The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4
The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.
nvdapple
CVE-2020-27918P3HIGHCVSS 7.8fixed in 14.0.12020-12-08
CVE-2020-27918 [HIGH] CWE-416 CVE-2020-27918: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2017-7090P3HIGHCVSS 7.5≤ 10.1.22017-10-23
CVE-2017-7090 [HIGH] CWE-200 CVE-2017-7090: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive cookie inf
nvdapple
CVE-2021-30848P3HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-19
CVE-2021-30848 [HIGH] CWE-787 CVE-2021-30848: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.
nvdapple
CVE-2026-28907P3HIGHCVSS 8.1fixed in 26.52026-05-11
CVE-2026-28907 [HIGH] CWE-20 CVE-2026-28907: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2006-3372P4MEDIUMCVSS 5.0PoCv2.0.4_419.32006-07-06
CVE-2006-3372 [MEDIUM] CVE-2006-3372: Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) vi
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.
nvd
CVE-2024-54479P3HIGHCVSS 7.5fixed in 18.22024-12-12
CVE-2024-54479 [HIGH] CVE-2024-54479: The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-24223P3HIGHCVSS 8.0fixed in 18.52025-05-12
CVE-2025-24223 [HIGH] CWE-352 CVE-2025-24223: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2024-27856P3HIGHCVSS 7.8fixed in 17.52025-01-15
CVE-2024-27856 [HIGH] CWE-94 CVE-2024-27856: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
nvdapple
CVE-2010-1396P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1396 [CRITICAL] CWE-399 CVE-2010-1396: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the contentEditable attribute and removing container elements.
nvd
CVE-2010-1397P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1397 [CRITICAL] CWE-399 CVE-2010-1397: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to a layout change during selection rendering and the DOCUMENT_POSITION_DISCONNECTED attrib
nvd
CVE-2025-7425P3HIGHCVSS 7.8v18.62025-07-30
CVE-2025-7425 [HIGH] CVE-2025-7425: Safari 18.6
Apple Security Update: About the security content of Safari 18.6
Product: Safari
Version: 18.6
CVE: CVE-2025-7425
Component: Safari 18.6
Impact: Processing a file may lead to memory corruption
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2025-43413P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43413 [HIGH] CWE-284 CVE-2025-43413: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A sandboxed app may be able to observe system-wide network connections.
nvd
CVE-2024-54502P3MEDIUMCVSS 6.5fixed in 18.22024-12-12
CVE-2024-54502 [MEDIUM] CWE-125 CVE-2024-54502: The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2007-0644P4HIGHCVSS 7.1PoCv2.0.4_419.32007-02-01
CVE-2007-0644 [HIGH] CVE-2007-0644: Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to c
Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.
nvd
CVE-2025-31238P3HIGHCVSS 7.3fixed in 18.52025-05-12
CVE-2025-31238 [HIGH] CWE-119 CVE-2025-31238: The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
nvdapple