Filtered by vendor Apple Subscriptions
Filtered by product Iphone Os Subscriptions
Total 4173 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-11115 2 Apple, Google 2 Iphone Os, Chrome 2025-01-02 8.8 High
Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege escalation via a series of UI gestures. (Chromium security severity: Medium)
CVE-2024-9957 2 Apple, Google 2 Iphone Os, Chrome 2025-01-02 8.8 High
Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2024-44212 1 Apple 6 Ipados, Iphone Os, Safari and 3 more 2024-12-20 5.3 Medium
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, visionOS 2.1, tvOS 18.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.
CVE-2024-44241 1 Apple 2 Ipados, Iphone Os 2024-12-18 9.8 Critical
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
CVE-2024-44242 1 Apple 2 Ipados, Iphone Os 2024-12-18 9.8 Critical
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
CVE-2024-44290 1 Apple 3 Ipados, Iphone Os, Watchos 2024-12-16 3.3 Low
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, watchOS 11.1. An app may be able to determine a user’s current location.
CVE-2024-44200 1 Apple 2 Ipados, Iphone Os 2024-12-13 5.5 Medium
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to read sensitive location information.
CVE-2024-44299 1 Apple 2 Ipados, Iphone Os 2024-12-13 8.8 High
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.
CVE-2024-44217 1 Apple 3 Ipad Os, Ipados, Iphone Os 2024-12-12 9.1 Critical
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may fill in passwords after failing authentication.
CVE-2024-44145 1 Apple 5 Ipad Os, Ipados, Iphone Os and 2 more 2024-12-12 5.7 Medium
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen.
CVE-2023-38136 1 Apple 3 Ipados, Iphone Os, Watchos 2024-12-12 7.8 High
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
CVE-2023-28208 1 Apple 3 Ipados, Iphone Os, Macos 2024-12-12 4.3 Medium
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may send a text from a secondary eSIM despite configuring a contact to use a primary eSIM.
CVE-2023-32438 1 Apple 4 Ipados, Iphone Os, Macos and 1 more 2024-12-12 5.5 Medium
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in tvOS 16.3, macOS Ventura 13.2, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.
CVE-2023-38261 1 Apple 3 Ipados, Iphone Os, Macos 2024-12-12 7.8 High
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.
CVE-2024-44123 1 Apple 3 Ipados, Iphone Os, Macos 2024-12-06 2.3 Low
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. A malicious app with root privileges may be able to access keyboard input and location information without user consent.
CVE-2022-42792 1 Apple 2 Ipados, Iphone Os 2024-12-06 5.5 Medium
This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive location information
CVE-2024-44251 1 Apple 2 Ipados, Iphone Os 2024-12-06 2.4 Low
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.
CVE-2023-32372 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2024-12-05 5.5 Medium
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. Processing an image may result in disclosure of process memory.
CVE-2023-32371 1 Apple 3 Ipados, Iphone Os, Macos 2024-12-05 6.3 Medium
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. An app may be able to break out of its sandbox.
CVE-2023-32368 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2024-12-05 5.5 Medium
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. Processing a 3D model may result in disclosure of process memory.