Apple Safari vulnerabilities
1,654 known vulnerabilities affecting apple/safari.
Total CVEs
1,654
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
51
Severity breakdown
CRITICAL211HIGH626MEDIUM796LOW20UNKNOWN1
Vulnerabilities
Page 78 of 83
CVE-2022-32868P4MEDIUMCVSS 4.3fixed in 16.0≥ unspecified, < 162022-09-20
CVE-2022-32868 [MEDIUM] CVE-2022-32868: A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16
A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. A website may be able to track users through Safari web extensions.
nvdapple
CVE-2023-42843P4MEDIUMCVSS 4.3fixed in 17.1≥ unspecified, < 17.12024-02-21
CVE-2023-42843 [MEDIUM] CWE-290 CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2025-30425P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30425 [MEDIUM] CWE-284 CVE-2025-30425: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
nvdapple
CVE-2024-23273P4MEDIUMCVSS 4.3fixed in 17.42024-03-08
CVE-2024-23273 [MEDIUM] CWE-295 CVE-2024-23273: This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.
nvdapple
CVE-2025-30467P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30467 [MEDIUM] CWE-451 CVE-2025-30467: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2025-43392P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43392 [MEDIUM] CWE-942 CVE-2025-43392: The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A website may exfiltrate image data cross-origin.
nvdapple
CVE-2024-8906P4MEDIUMCVSS 4.3v26.22025-12-12
CVE-2024-8906 [MEDIUM] CVE-2024-8906: Safari 26.2
Apple Security Update: About the security content of Safari 26.2
Product: Safari
Version: 26.2
CVE: CVE-2024-8906
Component: Safari Downloads
Impact: A download's origin may be incorrectly associated
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2025-43493P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43493 [MEDIUM] CWE-290 CVE-2025-43493: The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2026-28971P4MEDIUMCVSS 4.3fixed in 26.52026-05-11
CVE-2026-28971 [MEDIUM] CWE-1021 CVE-2026-28971: The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
nvd
CVE-2026-20691P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-20691 [MEDIUM] CWE-497 CVE-2026-20691: An authorization issue was addressed with improved state management. This issue is fixed in Safari 2
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2025-46299P4MEDIUMCVSS 4.3fixed in 26.22026-01-09
CVE-2025-46299 [MEDIUM] CWE-284 CVE-2025-46299: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Sa
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
nvdapple
CVE-2009-1706P4MEDIUMCVSS 5.0≤ 3.2.3v3.0+10 more2009-06-10
CVE-2009-1706 [MEDIUM] CWE-200 CVE-2009-1706: The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the
The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstances upon (1) disabling of the feature or (2) exit of the application, which makes it easier for remote web servers to track users via a cookie.
nvd
CVE-2007-3760P4MEDIUMCVSS 4.3≤ 3.0.32007-09-27
CVE-2007-3760 [MEDIUM] CWE-79 CVE-2007-3760: Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta U
Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to inject arbitrary web script or HTML via frame tags.
nvd
CVE-2009-1681P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1681 [MEDIUM] CVE-2009-1681: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites from loading third-party content into a subframe, which allows remote attackers to bypass the Same Origin Policy and conduct "clickjacking" attacks via a crafted HTML document.
nvd
CVE-2008-1002P4MEDIUMCVSS 4.3v0.8v0.9+14 more2008-03-19
CVE-2008-1002 [MEDIUM] CWE-79 CVE-2008-1002: Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1 allows remote attackers to injec
Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1 allows remote attackers to inject arbitrary web script or HTML via a crafted javascript: URL.
nvd
CVE-2008-1025P4MEDIUMCVSS 4.3v0.8v0.9+15 more2008-04-17
CVE-2008-1025 [MEDIUM] CWE-79 CVE-2008-1025: Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows rem
Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a colon in the hostname portion.
nvd
CVE-2009-1689P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1689 [MEDIUM] CWE-79 CVE-2009-1689: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving submission of a form to the about:blank URL, leading to security-context replacement.
nvd
CVE-2009-1695P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1695 [MEDIUM] CWE-79 CVE-2009-1695: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame contents after completion of a page transition.
nvd
CVE-2010-1764P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1764 [MEDIUM] CVE-2010-1764: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, follows multiple redirections during form submission, which allows remote web servers to obtain sensitive information by recording the form data.
nvd
CVE-2011-3243P4MEDIUMCVSS 4.3≤ 5.1v1.0+69 more2011-10-14
CVE-2011-3243 [MEDIUM] CWE-79 CVE-2011-3243: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
nvd