Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 44 of 83
CVE-2026-43745P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43745 [MEDIUM] CWE-787 CVE-2026-43745: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Sa
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43457P4MEDIUMCVSS 6.5fixed in 26.12025-11-04
CVE-2025-43457 [MEDIUM] CWE-416 CVE-2025-43457: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2026-43732P3MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43732 [MEDIUM] CWE-22 CVE-2026-43732: A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2,
A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2026-43740P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43740 [MEDIUM] CWE-119 CVE-2026-43740: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2016-10226P4HIGHCVSS 7.5v182017-04-03
CVE-2016-10226 [HIGH] CWE-125 CVE-2016-10226: JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote atta
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that is mishandled in the operatorString function, related to assembler/MacroAssemblerARM64.h, assembler/MacroAssemblerX86Common.h, and wa
nvd
CVE-2016-10222P4HIGHCVSS 7.5v182017-04-03
CVE-2016-10222 [HIGH] CWE-20 CVE-2016-10222: runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Rele
runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "type confusion" in the JSON.stringify function.
nvd
CVE-2014-3192P4HIGHCVSS 7.5v6.2.2v7.1.2+1 more2014-10-08
CVE-2014-3192 [HIGH] CWE-416 CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/Pro
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1153P4MEDIUMCVSS 6.8≤ 6.2.5v7.0+18 more2015-05-08
CVE-2015-1153 [MEDIUM] CVE-2015-1153: WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote
WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1152 and CVE-2015-1154.
nvd
CVE-2015-1152P4MEDIUMCVSS 6.8≤ 6.2.5v7.0+18 more2015-05-08
CVE-2015-1152 [MEDIUM] CVE-2015-1152: WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote
WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.
nvd
CVE-2013-0961P4MEDIUMCVSS 6.8≤ 6.0.2v1.0+70 more2013-03-15
CVE-2013-0961 [MEDIUM] CVE-2013-0961: WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a den
WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0960.
nvd
CVE-2013-0960P4MEDIUMCVSS 6.8≤ 6.0.2v1.0+70 more2013-03-15
CVE-2013-0960 [MEDIUM] CVE-2013-0960: WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a den
WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0961.
nvd
CVE-2019-8570P4MEDIUMCVSS 6.5fixed in 12.0.3≥ unspecified, < 12.02020-10-27
CVE-2019-8570 [MEDIUM] CVE-2019-8570: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iClou
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, iCloud for Windows 7.10, iTunes 12.9.3 for Windows, Safari 12.0.3, tvOS 12.1.2. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2016-7599P4MEDIUMCVSS 6.5≤ 10.0.12017-02-20
CVE-2016-7599 [MEDIUM] CWE-200 CVE-2016-7599: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP
nvdapple
CVE-2016-7598P4MEDIUMCVSS 6.5≤ 10.0.12017-02-20
CVE-2016-7598 [MEDIUM] CWE-200 CVE-2016-7598: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information from process memory via a crafted web site.
nvdapple
CVE-2020-9915P4MEDIUMCVSS 6.5fixed in 13.1.2≥ unspecified, < Safari 13.1.22020-10-16
CVE-2020-9915 [MEDIUM] CVE-2020-9915: An access issue existed in Content Security Policy. This issue was addressed with improved access re
An access issue existed in Content Security Policy. This issue was addressed with improved access restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may prevent Content Security Policy
nvdapple
CVE-2024-23280P4MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23280 [MEDIUM] CWE-74 CVE-2024-23280: An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 1
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2024-23254P4MEDIUMCVSS 6.5fixed in 17.42024-03-08
CVE-2024-23254 [MEDIUM] CVE-2024-23254: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
nvdapple
CVE-2024-40789P4MEDIUMCVSS 6.5fixed in 17.62024-07-29
CVE-2024-40789 [MEDIUM] CWE-125 CVE-2024-40789: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-43216P4MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43216 [MEDIUM] CWE-416 CVE-2025-43216: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43214P4MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43214 [MEDIUM] CWE-119 CVE-2025-43214: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple