cbcvebase.

Apple Safari vulnerabilities

1,654 known vulnerabilities affecting apple/safari.

Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1

Vulnerabilities

Page 34 of 83
CVE-2017-2419P3HIGHCVSS 7.5≤ 10.0.32017-04-02
CVE-2017-2419 [HIGH] CVE-2017-2419: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass a Content Security Policy protection mechanism via unspecified vectors.
nvdapple
CVE-2010-0048P3HIGHCVSS 8.8≤ 4.0.4v4.0+3 more2010-03-15
CVE-2010-0048 [HIGH] CWE-399 CVE-2010-0048: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.
nvd
CVE-2016-1762P3HIGHCVSS 8.1fixed in 9.12016-03-24
CVE-2016-1762 [HIGH] CWE-119 CVE-2016-1762: The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of servic The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2025-43480P3HIGHCVSS 8.1fixed in 26.12025-11-04
CVE-2025-43480 [HIGH] CWE-942 CVE-2025-43480: The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious website may exfiltrate data cross-origin.
nvdapple
CVE-2026-43735P3HIGHCVSS 8.1fixed in 26.5.22026-06-29
CVE-2026-43735 [HIGH] CWE-352 CVE-2026-43735: The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and i The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2010-1401P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1401 [CRITICAL] CWE-399 CVE-2010-1401: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple S Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the :first-letter pseudo-element.
nvd
CVE-2025-7424P3HIGHCVSS 7.5v18.62025-07-30
CVE-2025-7424 [HIGH] CVE-2025-7424: Safari 18.6 Apple Security Update: About the security content of Safari 18.6 Product: Safari Version: 18.6 CVE: CVE-2025-7424 Component: Safari 18.6 Impact: Processing a file may lead to memory corruption Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2017-17821P3CRITICALCVSS 9.8v462017-12-21
CVE-2017-17821 [CRITICAL] CWE-119 CVE-2017-17821: WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows re WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because it calls the FastBitVectorWordOwner::resizeSlow function (in WTF/wtf/FastBitVector.cpp) for a purpose other than initializing a bitvector
nvd
CVE-2024-44259P3HIGHCVSS 7.5fixed in 18.12024-10-28
CVE-2024-44259 [HIGH] CVE-2024-44259: This issue was addressed through improved state management. This issue is fixed in Safari 18.1, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. An attacker may be able to misuse a trust relationship to download malicious content.
nvd
CVE-2024-54508P3HIGHCVSS 7.5fixed in 18.22024-12-12
CVE-2024-54508 [HIGH] CWE-125 CVE-2024-54508: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-24169P3HIGHCVSS 7.5fixed in 18.32025-01-27
CVE-2025-24169 [HIGH] CWE-532 CVE-2025-24169: A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macO A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to bypass browser extension authentication.
nvdapple
CVE-2026-20652P3HIGHCVSS 7.5fixed in 26.32026-02-11
CVE-2026-20652 [HIGH] CWE-400 CVE-2026-20652: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.
nvdapple
CVE-2025-43502P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43502 [HIGH] CWE-284 CVE-2025-43502: A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26 A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.
nvdapple
CVE-2026-28944P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28944 [HIGH] CWE-119 CVE-2026-28944: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2020-6514P3MEDIUMCVSS 6.5fixed in 13.1.22020-07-22
CVE-2020-6514 [MEDIUM] CWE-200 CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
nvdapple
CVE-2010-1758P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1758 [CRITICAL] CWE-399 CVE-2010-1758: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving DOM Range objects.
nvd
CVE-2010-1761P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1761 [CRITICAL] CWE-399 CVE-2010-1761: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML document subtrees.
nvd
CVE-2010-1405P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1405 [CRITICAL] CWE-399 CVE-2010-1405: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML element that has custom vertical positioning.
nvd
CVE-2010-1392P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1392 [CRITICAL] CWE-399 CVE-2010-1392: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to HTML buttons and the first-letter CSS style.
nvd
CVE-2010-0052P3CRITICALCVSS 9.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0052 [CRITICAL] CWE-399 CVE-2010-0052: Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execu Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "callbacks for HTML elements."
nvd
Apple Safari vulnerabilities | cvebase