Apple Safari vulnerabilities
1,613 known vulnerabilities affecting apple/safari.
Total CVEs
1,613
CISA KEV
31
actively exploited
Public exploits
157
Exploited in wild
25
Severity breakdown
CRITICAL211HIGH615MEDIUM766LOW20UNKNOWN1
Vulnerabilities
Page 9 of 81
CVE-2024-40866MEDIUMCVSS 6.5fixed in 18.0fixed in 182024-09-17
CVE-2024-40866 [MEDIUM] CVE-2024-40866: The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiti
The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2024-44202MEDIUMCVSS 5.3fixed in 182024-09-17
CVE-2024-44202 [MEDIUM] CWE-287 CVE-2024-44202: An authentication issue was addressed with improved state management. This issue is fixed in Safari
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
nvdapple
CVE-2024-40817MEDIUMCVSS 6.1fixed in 17.62024-07-29
CVE-2024-40817 [MEDIUM] CWE-1021 CVE-2024-40817: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Montere
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2024-40780MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40780 [MEDIUM] CWE-125 CVE-2024-40780: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-40789MEDIUMCVSS 6.5fixed in 17.62024-07-29
CVE-2024-40789 [MEDIUM] CWE-125 CVE-2024-40789: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-40779MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40779 [MEDIUM] CWE-125 CVE-2024-40779: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-40782MEDIUMCVSS 6.5fixed in 17.62024-07-29
CVE-2024-40782 [MEDIUM] CWE-416 CVE-2024-40782: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-40785MEDIUMCVSS 6.1fixed in 17.62024-07-29
CVE-2024-40785 [MEDIUM] CWE-79 CVE-2024-40785: This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iP
This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvdapple
CVE-2024-40776MEDIUMCVSS 4.3fixed in 17.62024-07-29
CVE-2024-40776 [MEDIUM] CWE-416 CVE-2024-40776: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-40794MEDIUMCVSS 5.3fixed in 17.62024-07-29
CVE-2024-40794 [MEDIUM] CWE-287 CVE-2024-40794: This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.
nvdapple
CVE-2024-27851HIGHCVSS 8.8fixed in 17.52024-06-10
CVE-2024-27851 [HIGH] CWE-119 CVE-2024-27851: The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 an
The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-27808HIGHCVSS 8.8fixed in 17.52024-06-10
CVE-2024-27808 [HIGH] CWE-786 CVE-2024-27808: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2024-27833HIGHCVSS 8.8fixed in 17.52024-06-10
CVE-2024-27833 [HIGH] CWE-190 CVE-2024-27833: An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5
An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-27820HIGHCVSS 8.8fixed in 17.52024-06-10
CVE-2024-27820 [HIGH] CWE-119 CVE-2024-27820: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2024-27850MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27850 [MEDIUM] CWE-359 CVE-2024-27850: This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in
This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2024-27830MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27830 [MEDIUM] CVE-2024-27830: This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2024-27838MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27838 [MEDIUM] CWE-79 CVE-2024-27838: The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 a
The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2024-27844MEDIUMCVSS 5.5fixed in 17.52024-06-10
CVE-2024-27844 [MEDIUM] CVE-2024-27844: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5,
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A website's permission dialog may persist after navigation away from the site.
nvdapple
CVE-2024-27834MEDIUMCVSS 5.5fixed in 17.52024-05-14
CVE-2024-27834 [MEDIUM] CWE-277 CVE-2024-27834: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvdapple
CVE-2024-4558CRITICALCVSS 9.6fixed in 17.62024-05-07
CVE-2024-4558 [CRITICAL] CWE-416 CVE-2024-4558: Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potent
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvdapple