Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 35 of 83
CVE-2010-0043P3CRITICALCVSS 9.3≤ 4.0.4v4.0+4 more2010-03-15
CVE-2010-0043 [CRITICAL] CWE-94 CVE-2010-0043: ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to exe
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.
nvd
CVE-2011-1344P3MEDIUMCVSS 6.8≤ 5.0.4v1.0+59 more2011-03-10
CVE-2011-1344 [MEDIUM] CWE-399 CVE-2011-1344: Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for i
Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding children to a WBR tag and then removing the tag, related to text nodes, as demonstrated by Chaouki Bekra
nvd
CVE-2010-3808P3CRITICALCVSS 9.3≤ 5.0.2v5.0+51 more2010-11-22
CVE-2010-3808 [CRITICAL] CWE-94 CVE-2010-3808: WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on M
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of editing commands, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.
nvd
CVE-2006-2019P4MEDIUMCVSS 5.0PoCv1.3.1v2.0.32006-04-25
CVE-2006-2019 [MEDIUM] CVE-2006-2019: Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a d
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.
nvd
CVE-2017-7022P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7022 [HIGH] CWE-119 CVE-2017-7022: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7025P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7025 [HIGH] CWE-119 CVE-2017-7025: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7023P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7023 [HIGH] CWE-119 CVE-2017-7023: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-7024P3HIGHCVSS 7.8≤ 10.1.12017-07-20
CVE-2017-7024 [HIGH] CWE-119 CVE-2017-7024: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a craft
nvd
CVE-2017-2376P3HIGHCVSS 7.5≤ 10.0.32017-04-02
CVE-2017-2376 [HIGH] CVE-2017-2376: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar by leveraging text input during the loading of a page.
nvdapple
CVE-2016-7613P3HIGHCVSS 7.8≤ 10.0.02017-02-20
CVE-2016-7613 [HIGH] CWE-264 CVE-2016-7613: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages object-lifetime mishandling dur
nvd
CVE-2016-4676P3HIGHCVSS 7.5fixed in 10.0.1vbefore 10.0.12020-02-03
CVE-2016-4676 [HIGH] CWE-200 CVE-2016-4676: A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
nvd
CVE-2018-4277P3HIGHCVSS 7.5fixed in 11.1.12019-01-11
CVE-2018-4277 [HIGH] CWE-20 CVE-2018-4277: In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sie
In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
nvdapple
CVE-2020-9911P3HIGHCVSS 7.5fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9911 [HIGH] CVE-2020-9911: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy.
nvdapple
CVE-2010-1404P3CRITICALCVSS 9.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1404 [CRITICAL] CWE-399 CVE-2010-1404: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruc
nvd
CVE-2025-24213P3HIGHCVSS 7.8fixed in 18.4fixed in 18.52025-03-31
CVE-2025-24213 [HIGH] CWE-843 CVE-2025-24213: This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 1
This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption.
nvdapple
CVE-2020-3864P3HIGHCVSS 7.8fixed in 13.0.5≥ unspecified, < 13.02020-10-27
CVE-2020-3864 [HIGH] CWE-346 CVE-2020-3864: A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
nvd
CVE-2009-1704P3CRITICALCVSS 9.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1704 [CRITICAL] CWE-94 CVE-2009-1704: CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in
CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by placing it in an image file.
nvd
CVE-2026-28962P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28962 [HIGH] CWE-200 CVE-2026-28962: This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS
This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2009-0321P4MEDIUMCVSS 4.3PoCv3.2.12009-01-28
CVE-2009-0321 [MEDIUM] CWE-59 CVE-2009-0321: Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of s
Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.
nvd
CVE-2009-1690P3CRITICALCVSS 9.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1690 [CRITICAL] CWE-399 CVE-2009-1690: Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified
nvd