Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 73 of 84
CVE-2016-7592P4MEDIUMCVSS 4.3≤ 10.0.12017-02-20
CVE-2016-7592 [MEDIUM] CWE-200 CVE-2016-7592: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.
nvdapple
CVE-2014-1345P4MEDIUMCVSS 4.3≤ 6.1.4v6.0+14 more2014-07-01
CVE-2014-1345 [MEDIUM] CVE-2014-1345: WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properl
WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5fixed in 4.0.42009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2020-3887P4MEDIUMCVSS 4.3fixed in 13.1≥ unspecified, < Safari 13.12020-04-01
CVE-2020-3887 [MEDIUM] CVE-2020-3887: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly associated.
nvd
CVE-2025-43438P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43438 [MEDIUM] CWE-416 CVE-2025-43438: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43441P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43441 [MEDIUM] CWE-119 CVE-2025-43441: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-43535P4MEDIUMCVSS 4.3fixed in 26.22025-12-17
CVE-2025-43535 [MEDIUM] CVE-2025-43535: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2026-20664P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-20664 [MEDIUM] CWE-787 CVE-2026-20664: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28859P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-28859 [MEDIUM] CWE-125 CVE-2026-28859: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2025-43536P4MEDIUMCVSS 4.3fixed in 26.22025-12-17
CVE-2025-43536 [MEDIUM] CWE-416 CVE-2025-43536: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2026-65334P4MEDIUMCVSS 4.3fixed in 26.6.12026-08-17
CVE-2026-65334 [MEDIUM] CWE-119 CVE-2026-65334: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-20635P4MEDIUMCVSS 4.3fixed in 26.32026-02-11
CVE-2026-20635 [MEDIUM] CWE-119 CVE-2026-20635: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2009-2420P4MEDIUMCVSS 5.8v3.2.32009-07-09
CVE-2009-2420 [MEDIUM] CVE-2009-2420: Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attac
Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag, possibly a related issue to CVE-2009-1703.
nvd
CVE-2009-1715P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1715 [MEDIUM] CWE-79 CVE-2009-1715: Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allow
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to script execution with incorrect privileges.
nvd
CVE-2009-1696P4MEDIUMCVSS 5.0≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1696 [MEDIUM] CWE-310 CVE-2009-1696: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in JavaScript applications, which makes it easier for remote web servers to track the behavior of a Safari user during a session.
nvd
CVE-2005-3897P4HIGHCVSS 7.8v2.0.22005-11-29
CVE-2005-3897 [HIGH] CVE-2005-3897: Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Java
Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function.
nvd
CVE-2011-1190P4MEDIUMCVSS 5.0fixed in 5.0.62011-03-11
CVE-2011-1190 [MEDIUM] CWE-200 CVE-2011-1190: The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypas
The Web Workers implementation in Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
nvd
CVE-2005-0976P4MEDIUMCVSS 5.0v1.22005-05-02
CVE-2005-0976 [MEDIUM] CVE-2005-0976: AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup Omni
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.
nvd
CVE-2024-27844P4MEDIUMCVSS 5.5fixed in 17.52024-06-10
CVE-2024-27844 [MEDIUM] CVE-2024-27844: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5,
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A website's permission dialog may persist after navigation away from the site.
nvdapple
CVE-2024-44192P4MEDIUMCVSS 5.5fixed in 18.0fixed in 182025-03-10
CVE-2024-44192 [MEDIUM] CWE-400 CVE-2024-44192: The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18
The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple