Apple Safari vulnerabilities
1,677 known vulnerabilities affecting apple/safari.
Total CVEs
1,677
CISA KEV
31
actively exploited
Public exploits
168
Exploited in wild
52
Severity breakdown
CRITICAL211HIGH628MEDIUM815LOW22UNKNOWN1
Vulnerabilities
Page 79 of 84
CVE-2023-42843P4MEDIUMCVSS 4.3fixed in 17.1≥ unspecified, < 17.12024-02-21
CVE-2023-42843 [MEDIUM] CWE-290 CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2025-30425P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30425 [MEDIUM] CWE-284 CVE-2025-30425: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
nvdapple
CVE-2024-23273P4MEDIUMCVSS 4.3fixed in 17.42024-03-08
CVE-2024-23273 [MEDIUM] CWE-295 CVE-2024-23273: This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.
nvdapple
CVE-2025-43421P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43421 [MEDIUM] CWE-125 CVE-2025-43421: Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari
Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-30467P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30467 [MEDIUM] CWE-451 CVE-2025-30467: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2024-8906P4MEDIUMCVSS 4.3v26.22025-12-12
CVE-2024-8906 [MEDIUM] CVE-2024-8906: Safari 26.2
Apple Security Update: About the security content of Safari 26.2
Product: Safari
Version: 26.2
CVE: CVE-2024-8906
Component: Safari Downloads
Impact: A download's origin may be incorrectly associated
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2025-43503P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43503 [MEDIUM] CWE-290 CVE-2025-43503: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2026-28971P4MEDIUMCVSS 4.3fixed in 26.52026-05-11
CVE-2026-28971 [MEDIUM] CWE-1021 CVE-2026-28971: The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
nvd
CVE-2026-20691P4MEDIUMCVSS 4.3fixed in 26.42026-03-25
CVE-2026-20691 [MEDIUM] CWE-497 CVE-2026-20691: An authorization issue was addressed with improved state management. This issue is fixed in Safari 2
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2026-28984P4MEDIUMCVSS 4.3fixed in 26.52026-08-17
CVE-2026-28984 [MEDIUM] CWE-119 CVE-2026-28984: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2006-1552P4MEDIUMCVSS 5.0v1.0v1.1+10 more2006-03-31
CVE-2006-1552 [MEDIUM] CWE-189 CVE-2006-1552: Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a d
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
nvd
CVE-2009-1706P4MEDIUMCVSS 5.0≤ 3.2.3v3.0+10 more2009-06-10
CVE-2009-1706 [MEDIUM] CWE-200 CVE-2009-1706: The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the
The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstances upon (1) disabling of the feature or (2) exit of the application, which makes it easier for remote web servers to track users via a cookie.
nvd
CVE-2007-3760P4MEDIUMCVSS 4.3≤ 3.0.32007-09-27
CVE-2007-3760 [MEDIUM] CWE-79 CVE-2007-3760: Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta U
Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to inject arbitrary web script or HTML via frame tags.
nvd
CVE-2009-1681P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1681 [MEDIUM] CVE-2009-1681: WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 thr
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites from loading third-party content into a subframe, which allows remote attackers to bypass the Same Origin Policy and conduct "clickjacking" attacks via a crafted HTML document.
nvd
CVE-2008-1025P4MEDIUMCVSS 4.3v0.8v0.9+15 more2008-04-17
CVE-2008-1025 [MEDIUM] CWE-79 CVE-2008-1025: Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows rem
Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a colon in the hostname portion.
nvd
CVE-2009-1689P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1689 [MEDIUM] CWE-79 CVE-2009-1689: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving submission of a form to the about:blank URL, leading to security-context replacement.
nvd
CVE-2009-1695P4MEDIUMCVSS 4.3≤ 4.0_betav0.8+24 more2009-06-10
CVE-2009-1695 [MEDIUM] CWE-79 CVE-2009-1695: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame contents after completion of a page transition.
nvd
CVE-2010-1764P4MEDIUMCVSS 4.3≤ 4.0.5v4.0+5 more2010-06-11
CVE-2010-1764 [MEDIUM] CVE-2010-1764: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac O
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, follows multiple redirections during form submission, which allows remote web servers to obtain sensitive information by recording the form data.
nvd
CVE-2011-3243P4MEDIUMCVSS 4.3≤ 5.1v1.0+69 more2011-10-14
CVE-2011-3243 [MEDIUM] CWE-79 CVE-2011-3243: Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
nvd
CVE-2013-1012P4MEDIUMCVSS 4.3≤ 6.0.4v6.0+3 more2013-06-05
CVE-2013-1012 [MEDIUM] CWE-79 CVE-2013-1012: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0.5 allows remote attack
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0.5 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.
nvd