Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 76 of 83
CVE-2019-8898P4MEDIUMCVSS 4.3fixed in 13.0.4≥ unspecified, < 13.02020-10-27
CVE-2019-8898 [MEDIUM] CVE-2019-8898: An information disclosure issue existed in the handling of the Storage Access API. This issue was ad
An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
nvdapple
CVE-2025-43421P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43421 [MEDIUM] CWE-125 CVE-2025-43421: Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari
Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-43503P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43503 [MEDIUM] CWE-290 CVE-2025-43503: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2026-43708P4MEDIUMCVSS 4.3fixed in 26.5.22026-06-29
CVE-2026-43708 [MEDIUM] CWE-20 CVE-2026-43708: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2026-28861P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-28861 [MEDIUM] CWE-79 CVE-2026-28861: A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.
nvd
CVE-2026-28917P4MEDIUMCVSS 4.3fixed in 26.52026-05-11
CVE-2026-28917 [MEDIUM] CWE-20 CVE-2026-28917: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-28871P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-28871 [MEDIUM] CWE-79 CVE-2026-28871: A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and
A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.
nvd
CVE-2009-2421P4MEDIUMCVSS 5.0v3.2.32009-07-09
CVE-2009-2421 [MEDIUM] CWE-20 CVE-2009-2421: The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote
The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in a URL fragment for an unspecified protocol.
nvd
CVE-2011-3234P4MEDIUMCVSS 5.0fixed in 5.1.12011-09-19
CVE-2011-3234 [MEDIUM] CWE-125 CVE-2011-3234: Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to c
Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2006-6238P4MEDIUMCVSS 5.0v2.0.42006-12-03
CVE-2006-6238 [MEDIUM] CVE-2006-6238: The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated
The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width, a variant of CVE-2006-6077.
nvd
CVE-2009-2072P4MEDIUMCVSS 5.4≤ 3.2.1v0.8+52 more2009-06-15
CVE-2009-2072 [MEDIUM] CWE-287 CVE-2009-2072: Apple Safari does not require a cached certificate before displaying a lock icon for an https web si
Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.
nvd
CVE-2009-1697P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1697 [MEDIUM] CWE-20 CVE-2009-1697: CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and
CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting (XSS) attacks that depend on communication with arbitrary web sites on
nvd
CVE-2010-1416P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1416 [MEDIUM] CWE-264 CVE-2010-1416: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict the reading of a canvas that contains an SVG image pattern from a different web site, which allows remote attackers to read images from other sites via a crafted canvas, related to a "cross-site image capture issue."
nvd
CVE-2010-1762P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1762 [MEDIUM] CWE-79 CVE-2010-1762: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML in a TEXTAREA element.
nvd
CVE-2010-0544P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-0544 [MEDIUM] CWE-79 CVE-2010-0544: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to a malformed URL.
nvd
CVE-2010-1394P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1394 [MEDIUM] CWE-79 CVE-2010-1394: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML document fragments.
nvd
CVE-2010-1418P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1418 [MEDIUM] CWE-79 CVE-2010-1418: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via a FRAME element with a SRC attribute composed of a javascript: sequence preceded by spaces.
nvd
CVE-2010-1389P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1389 [MEDIUM] CWE-79 CVE-2010-1389: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) paste or (2) drag-and-drop operation for a selection.
nvd
CVE-2010-1395P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1395 [MEDIUM] CWE-79 CVE-2010-1395: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving DOM constructor objects, related to a "scope management issue."
nvd
CVE-2012-0640P4MEDIUMCVSS 5.0≤ 5.1.3v1.0+71 more2012-03-12
CVE-2012-0640 [MEDIUM] CWE-200 CVE-2012-0640: WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers"
WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remote web servers to track users via a cookie.
nvd