Apple Safari vulnerabilities
1,613 known vulnerabilities affecting apple/safari.
Total CVEs
1,613
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH615MEDIUM766LOW20UNKNOWN1
Vulnerabilities
Page 5 of 81
CVE-2025-43327MEDIUMCVSS 6.5fixed in 26.0fixed in 262025-09-15
CVE-2025-43327 [MEDIUM] CWE-451 CVE-2025-43327: The issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26
The issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2025-43368MEDIUMCVSS 4.3fixed in 26.0fixed in 262025-09-15
CVE-2025-43368 [MEDIUM] CWE-416 CVE-2025-43368: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-31254MEDIUMCVSS 5.4fixed in 26.0fixed in 262025-09-15
CVE-2025-31254 [MEDIUM] CWE-863 CVE-2025-31254: This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and
This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.
nvdapple
CVE-2025-43272MEDIUMCVSS 6.5fixed in 26.0fixed in 262025-09-15
CVE-2025-43272 [MEDIUM] CWE-119 CVE-2025-43272: The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-31273HIGHCVSS 8.8fixed in 18.62025-07-30
CVE-2025-31273 [HIGH] CWE-119 CVE-2025-31273: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2025-43227HIGHCVSS 7.5fixed in 18.62025-07-30
CVE-2025-43227 [HIGH] CWE-359 CVE-2025-43227: This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2025-7424HIGHCVSS 7.5v18.62025-07-30
CVE-2025-7424 [HIGH] CVE-2025-7424: Safari 18.6
Apple Security Update: About the security content of Safari 18.6
Product: Safari
Version: 18.6
CVE: CVE-2025-7424
Component: Safari 18.6
Impact: Processing a file may lead to memory corruption
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2025-31278HIGHCVSS 8.8fixed in 18.62025-07-30
CVE-2025-31278 [HIGH] CWE-119 CVE-2025-31278: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2025-31277HIGHCVSS 8.8KEVfixed in 18.62025-07-30
CVE-2025-31277 [HIGH] CWE-119 CVE-2025-31277: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2025-7425HIGHCVSS 7.8v18.62025-07-30
CVE-2025-7425 [HIGH] CVE-2025-7425: Safari 18.6
Apple Security Update: About the security content of Safari 18.6
Product: Safari
Version: 18.6
CVE: CVE-2025-7425
Component: Safari 18.6
Impact: Processing a file may lead to memory corruption
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2025-24188MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-24188 [MEDIUM] CWE-703 CVE-2025-24188: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia
A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43213MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43213 [MEDIUM] CWE-119 CVE-2025-43213: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43265MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43265 [MEDIUM] CWE-125 CVE-2025-43265: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.
nvdapple
CVE-2025-43216MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43216 [MEDIUM] CWE-416 CVE-2025-43216: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43211MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43211 [MEDIUM] CWE-770 CVE-2025-43211: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2025-43214MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43214 [MEDIUM] CWE-119 CVE-2025-43214: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43229MEDIUMCVSS 6.1fixed in 18.62025-07-30
CVE-2025-43229 [MEDIUM] CWE-79 CVE-2025-43229: This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macO
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2025-43228MEDIUMCVSS 4.3fixed in 18.62025-07-30
CVE-2025-43228 [MEDIUM] CWE-451 CVE-2025-43228: The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18
The issue was addressed with improved UI. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2025-43212MEDIUMCVSS 6.5fixed in 18.62025-07-30
CVE-2025-43212 [MEDIUM] CWE-119 CVE-2025-43212: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43240MEDIUMCVSS 6.2fixed in 18.62025-07-30
CVE-2025-43240 [MEDIUM] CWE-703 CVE-2025-43240: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia
A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
nvdapple