cbcvebase.

Apple Safari vulnerabilities

1,677 known vulnerabilities affecting apple/safari.

Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1

Vulnerabilities

Page 54 of 84
CVE-2025-31217P4MEDIUMCVSS 6.5fixed in 18.52025-05-12
CVE-2025-31217 [MEDIUM] CWE-20 CVE-2025-31217: The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2024-27850P4MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27850 [MEDIUM] CWE-359 CVE-2024-27850: This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2024-27830P4MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27830 [MEDIUM] CVE-2024-27830: This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2025-31215P4MEDIUMCVSS 6.5fixed in 18.52025-05-12
CVE-2025-31215 [MEDIUM] CWE-20 CVE-2025-31215: The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-54467P4MEDIUMCVSS 6.5fixed in 18.0fixed in 182025-03-10
CVE-2024-54467 [MEDIUM] CWE-200 CVE-2024-54467: A cookie management issue was addressed with improved state management. This issue is fixed in Safar A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.
nvdapple
CVE-2023-40385P4MEDIUMCVSS 6.5fixed in 17.0≥ unspecified, < 172024-01-10
CVE-2023-40385 [MEDIUM] CWE-200 CVE-2023-40385: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Sa This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
nvdapple
CVE-2025-43440P4MEDIUMCVSS 6.5fixed in 26.12025-11-04
CVE-2025-43440 [MEDIUM] CWE-79 CVE-2025-43440: This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPad This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-43327P4MEDIUMCVSS 6.5fixed in 26.0fixed in 262025-09-15
CVE-2025-43327 [MEDIUM] CWE-451 CVE-2025-43327: The issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26 The issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2026-43712P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43712 [MEDIUM] CWE-125 CVE-2026-43712: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28946P4MEDIUMCVSS 6.5fixed in 26.52026-05-11
CVE-2026-28946 [MEDIUM] CWE-416 CVE-2026-28946: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-31205P4MEDIUMCVSS 6.5fixed in 18.52025-05-12
CVE-2025-31205 [MEDIUM] CWE-352 CVE-2025-31205: The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A malicious website may exfiltrate data cross-origin.
nvdapple
CVE-2025-46298P4MEDIUMCVSS 6.5fixed in 26.22026-01-09
CVE-2025-46298 [MEDIUM] CWE-119 CVE-2025-46298: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2026-43663P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43663 [MEDIUM] CWE-119 CVE-2026-43663: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-39872P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-39872 [MEDIUM] CWE-119 CVE-2026-39872: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43746P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43746 [MEDIUM] CWE-416 CVE-2026-43746: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2007-3187P4HIGHCVSS 7.5v3.02007-06-12
CVE-2007-3187 [HIGH] CVE-2007-3187: Multiple unspecified vulnerabilities in Apple Safari for Windows allow remote attackers to cause a d Multiple unspecified vulnerabilities in Apple Safari for Windows allow remote attackers to cause a denial of service or execute arbitrary code, possibly involving memory corruption, and a different issue from CVE-2007-3185 and CVE-2007-3186. NOTE: as of 20070612, the original disclosure has no actionable information. However, since it is from a well-known resea
nvd
CVE-2011-3885P4HIGHCVSS 7.5fixed in 5.1.42011-10-25
CVE-2011-3885 [HIGH] CWE-416 CVE-2011-3885: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.
nvd
CVE-2011-3966P4HIGHCVSS 7.5fixed in 6.02012-02-09
CVE-2011-3966 [HIGH] CWE-416 CVE-2011-3966: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sheets (CSS) token-sequence data.
nvd
CVE-2011-2860P4HIGHCVSS 7.5fixed in 5.1.42011-09-19
CVE-2011-2860 [HIGH] CWE-416 CVE-2011-2860: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to table styles.
nvd
CVE-2011-3913P4HIGHCVSS 7.5fixed in 6.02011-12-13
CVE-2011-3913 [HIGH] CWE-416 CVE-2011-3913: Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to Range handling.
nvd
Apple Safari vulnerabilities | cvebase