iOS
by Apple Inc.
CVEs (2,979)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24141 | 0.00 | — | 0.00 | Jan 27, 2025 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked. | |||
| CVE-2024-40839 | 0.00 | — | 0.00 | Jan 15, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen. | |||
| CVE-2024-44136 | 0.00 | — | 0.00 | Jan 15, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection. | |||
| CVE-2024-54503 | 0.00 | — | 0.00 | Dec 11, 2024 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2. Muting a call while ringing may not result in mute being enabled. | |||
| CVE-2024-44261 | 0.00 | — | 0.00 | Oct 28, 2024 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen. | |||
| CVE-2024-44251 | 0.00 | — | 0.00 | Oct 28, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen. | |||
| CVE-2024-40851 | 0.00 | — | 0.00 | Oct 28, 2024 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen. | |||
| CVE-2024-40867 | 0.00 | — | 0.02 | Oct 28, 2024 | A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox. | |||
| CVE-2024-44204 | 0.00 | — | 0.02 | Oct 3, 2024 | A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read aloud by VoiceOver. | |||
| CVE-2024-44124 | 0.00 | — | 0.00 | Sep 16, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing. | |||
| CVE-2024-40852 | 0.00 | — | 0.00 | Sep 16, 2024 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access. | |||
| CVE-2024-44180 | 0.00 | — | 0.00 | Sep 16, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen. | |||
| CVE-2024-44139 | 0.00 | — | 0.00 | Sep 16, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen. | |||
| CVE-2024-27879 | 0.00 | — | 0.00 | Sep 16, 2024 | The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker may be able to cause unexpected app termination. | |||
| CVE-2024-40840 | 0.00 | — | 0.00 | Sep 16, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data. | |||
| CVE-2024-27874 | 0.00 | — | 0.00 | Sep 16, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to cause a denial-of-service. | |||
| CVE-2024-44171 | 0.00 | — | 0.00 | Sep 16, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features. | |||
| CVE-2024-44147 | 0.00 | — | 0.00 | Sep 16, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network. | |||
| CVE-2024-40826 | 0.00 | — | 0.00 | Sep 16, 2024 | A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An unencrypted document may be written to a temporary file when using print preview. | |||
| CVE-2024-44131 | 0.00 | — | 0.00 | Sep 16, 2024 | This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sensitive user data. |
- CVE-2025-24141Jan 27, 2025risk 0.00cvss —epss 0.00
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.
- CVE-2024-40839Jan 15, 2025risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.
- CVE-2024-44136Jan 15, 2025risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.
- CVE-2024-54503Dec 11, 2024risk 0.00cvss —epss 0.00
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2. Muting a call while ringing may not result in mute being enabled.
- CVE-2024-44261Oct 28, 2024risk 0.00cvss —epss 0.00
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.
- CVE-2024-44251Oct 28, 2024risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.
- CVE-2024-40851Oct 28, 2024risk 0.00cvss —epss 0.00
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.
- CVE-2024-40867Oct 28, 2024risk 0.00cvss —epss 0.02
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.
- CVE-2024-44204Oct 3, 2024risk 0.00cvss —epss 0.02
A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read aloud by VoiceOver.
- CVE-2024-44124Sep 16, 2024risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing.
- CVE-2024-40852Sep 16, 2024risk 0.00cvss —epss 0.00
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.
- CVE-2024-44180Sep 16, 2024risk 0.00cvss —epss 0.00
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.
- CVE-2024-44139Sep 16, 2024risk 0.00cvss —epss 0.00
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.
- CVE-2024-27879Sep 16, 2024risk 0.00cvss —epss 0.00
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker may be able to cause unexpected app termination.
- CVE-2024-40840Sep 16, 2024risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
- CVE-2024-27874Sep 16, 2024risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to cause a denial-of-service.
- CVE-2024-44171Sep 16, 2024risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.
- CVE-2024-44147Sep 16, 2024risk 0.00cvss —epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network.
- CVE-2024-40826Sep 16, 2024risk 0.00cvss —epss 0.00
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An unencrypted document may be written to a temporary file when using print preview.
- CVE-2024-44131Sep 16, 2024risk 0.00cvss —epss 0.00
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sensitive user data.
Page 47 of 149