Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 71 of 83
CVE-2009-2841P4MEDIUMCVSS 5.0≤ 4.0.3v0.8+58 more2009-11-13
CVE-2009-2841 [MEDIUM] CVE-2009-2841: The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before
The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a
nvd
CVE-2021-30861P4MEDIUMCVSS 5.5fixed in 15.0.02021-08-24
CVE-2021-30861 [MEDIUM] CVE-2021-30861: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may bypass Gatekeeper checks.
nvdapple
CVE-2010-1421P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1421 [MEDIUM] CVE-2010-1421: The execCommand JavaScript function in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10
The execCommand JavaScript function in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict remote execution of clipboard commands, which allows remote attackers to modify the clipboard via a crafted HTML document.
nvd
CVE-2012-0676P4MEDIUMCVSS 5.0≤ 5.1.6v1.0+74 more2012-05-11
CVE-2012-0676 [MEDIUM] CWE-20 CVE-2012-0676: WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing
WebKit in Apple Safari before 5.1.7 does not properly track state information during the processing of form input, which allows remote attackers to fill in form fields on the pages of arbitrary web sites via unspecified vectors.
nvd
CVE-2018-4279P4MEDIUMCVSS 5.3fixed in 11.1.2vVersions prior to: Safari 11.1.22019-04-03
CVE-2018-4279 [MEDIUM] CWE-20 CVE-2018-4279: An inconsistent user interface issue was addressed with improved state management. This issue affect
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2.
nvdapple
CVE-2019-8725P4MEDIUMCVSS 5.3fixed in 13.0.1≥ unspecified, < Safari 13.0.12019-12-18
CVE-2019-8725 [MEDIUM] CVE-2019-8725: The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Sa
The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing history.
nvdapple
CVE-2026-20608P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20608 [MEDIUM] CWE-770 CVE-2026-20608: This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2023-27932P4MEDIUMCVSS 5.5fixed in 16.4≥ unspecified, < 16.42023-05-08
CVE-2023-27932 [MEDIUM] CWE-346 CVE-2023-27932: This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3,
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.
nvdapple
CVE-2011-3887P4MEDIUMCVSS 5.0fixed in 5.1.42011-10-25
CVE-2011-3887 [MEDIUM] CWE-565 CVE-2011-3887: Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote att
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
nvd
CVE-2010-1408P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1408 [MEDIUM] CVE-2010-1408: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to bypass intended restrictions on outbound connections to "non-default TCP ports" via a crafted port number, related to an "integer truncation issue." NOTE: this may overlap CVE-2010-1099.
nvd
CVE-2012-0647P4MEDIUMCVSS 5.0≤ 5.1.3v1.0+71 more2012-03-12
CVE-2012-0647 [MEDIUM] CWE-200 CVE-2012-0647: WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP auth
WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
nvd
CVE-2015-5764P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5764 [MEDIUM] CWE-20 CVE-2015-5764: The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspeci
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767.
nvd
CVE-2025-31257P4MEDIUMCVSS 4.7fixed in 18.52025-05-12
CVE-2025-31257 [MEDIUM] CWE-119 CVE-2025-31257: This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5
This issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2016-7650P4MEDIUMCVSS 4.7≤ 10.0.12017-02-20
CVE-2016-7650 [MEDIUM] CWE-79 CVE-2016-7650: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "Safari Reader" component, which allows remote attackers to conduct UXSS attacks via a crafted web site.
nvdapple
CVE-2015-5820P4MEDIUMCVSS 4.3≤ 8.0.82015-09-18
CVE-2015-5820 [MEDIUM] CWE-20 CVE-2015-5820: WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) t
WebKit in Apple iOS before 9 allows remote attackers to trigger a dialing action via a crafted (1) tel://, (2) facetime://, or (3) facetime-audio:// URL.
nvd
CVE-2011-3888P4MEDIUMCVSS 6.8fixed in 5.1.42011-10-25
CVE-2011-3888 [MEDIUM] CWE-416 CVE-2011-3888: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attack
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.
nvd
CVE-2011-1204P4MEDIUMCVSS 6.8fixed in 5.0.62011-03-11
CVE-2011-1204 [MEDIUM] CWE-20 CVE-2011-1204: Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers
Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-2359P4MEDIUMCVSS 6.8fixed in 5.1.12011-08-03
CVE-2011-2359 [MEDIUM] CWE-20 CVE-2011-2359: Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows
Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-3958P4MEDIUMCVSS 6.8fixed in 6.02012-02-09
CVE-2011-3958 [MEDIUM] CWE-416 CVE-2011-3958: Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a c
Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2020-3885P4MEDIUMCVSS 4.3fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-3885 [MEDIUM] CWE-670 CVE-2020-3885: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.
nvd