Apple Safari vulnerabilities

1,546 known vulnerabilities affecting apple/safari.

Total CVEs
1,546
CISA KEV
27
actively exploited
Public exploits
145
Exploited in wild
21
Severity breakdown
CRITICAL211HIGH575MEDIUM741LOW19

Vulnerabilities

Page 4 of 78
CVE-2025-43368MEDIUMCVSS 4.3fixed in 26.0fixed in 262025-09-15
CVE-2025-43368 [MEDIUM] CWE-416 CVE-2025-43368: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-31254MEDIUMCVSS 5.4fixed in 26.0fixed in 262025-09-15
CVE-2025-31254 [MEDIUM] CWE-863 CVE-2025-31254: This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.
cvelistv5nvd
CVE-2025-31273HIGHCVSS 8.8fixed in 18.62025-07-30
CVE-2025-31273 [HIGH] CWE-119 CVE-2025-31273: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd
CVE-2025-31278HIGHCVSS 8.8fixed in 18.62025-07-30
CVE-2025-31278 [HIGH] CWE-119 CVE-2025-31278: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd
CVE-2025-31277HIGHCVSS 8.8KEVfixed in 18.62025-07-30
CVE-2025-31277 [HIGH] CWE-119 CVE-2025-31277: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd
CVE-2025-43227HIGHCVSS 7.5fixed in 18.62025-07-30
CVE-2025-43227 [HIGH] CWE-359 CVE-2025-43227: This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.
cvelistv5nvd
CVE-2025-43240MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43240 [MEDIUM] CWE-703 CVE-2025-43240: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
cvelistv5nvd
CVE-2025-43211MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43211 [MEDIUM] CWE-770 CVE-2025-43211: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.
cvelistv5nvd
CVE-2025-43265MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43265 [MEDIUM] CWE-125 CVE-2025-43265: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18 An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.
cvelistv5nvd
CVE-2025-24188MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-24188 [MEDIUM] CWE-703 CVE-2025-24188: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43213MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43213 [MEDIUM] CWE-119 CVE-2025-43213: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43214MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43214 [MEDIUM] CWE-119 CVE-2025-43214: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43228MEDIUMCVSS 4.3fixed in 18.62025-07-30
CVE-2025-43228 [MEDIUM] CWE-451 CVE-2025-43228: The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18 The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing.
cvelistv5nvd
CVE-2025-43216MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43216 [MEDIUM] CWE-416 CVE-2025-43216: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43212MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43212 [MEDIUM] CWE-119 CVE-2025-43212: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43229MEDIUMCVSS 6.1fixed in 18.62025-07-30
CVE-2025-43229 [MEDIUM] CWE-79 CVE-2025-43229: This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macO This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting.
cvelistv5nvd
CVE-2025-6558HIGHCVSS 8.8KEVfixed in 18.62025-07-15
CVE-2025-6558 [HIGH] CWE-20 CVE-2025-6558: Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-30466CRITICALCVSS 9.8fixed in 18.42025-05-29
CVE-2025-30466 [CRITICAL] CWE-346 CVE-2025-30466: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.
cvelistv5nvd
CVE-2025-24189HIGHCVSS 8.8fixed in 18.32025-05-19
CVE-2025-24189 [HIGH] CWE-119 CVE-2025-24189: The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd
CVE-2025-24223HIGHCVSS 8.0fixed in 18.52025-05-12
CVE-2025-24223 [HIGH] CWE-352 CVE-2025-24223: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
cvelistv5nvd