iOS Apple iOS The iOS Operating System used by iPhones.

Do you want an email whenever new security vulnerabilities are reported in Apple iOS?

By the Year

In 2023 there have been 77 vulnerabilities in Apple iOS with an average score of 6.5 out of ten. Last year iOS had 242 security vulnerabilities published. Right now, iOS is on track to have less security vulnerabilities in 2023 than it did last year. Last year, the average CVE base score was greater by 0.54

Year Vulnerabilities Average Score
2023 77 6.54
2022 242 7.09
2021 383 7.01
2020 252 7.09
2019 349 7.48
2018 99 7.39

It may take a day or so for new iOS vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple iOS Security Vulnerabilities

An integer overflow was addressed with improved input validation

CVE-2022-46720 8.6 - High - May 08, 2023

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox

Integer Overflow or Wraparound

A privacy issue was addressed with improved private data redaction for log entries

CVE-2023-23537 5.5 - Medium - May 08, 2023

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3, macOS Big Sur 11.7.5, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information

The issue was addressed with improved bounds checks

CVE-2023-23536 7.8 - High - May 08, 2023

The issue was addressed with improved bounds checks. This issue is fixed in macOS Big Sur 11.7.5, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. An app may be able to execute arbitrary code with kernel privileges

The issue was addressed with improved memory handling

CVE-2023-23535 5.5 - Medium - May 08, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.6, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, macOS Big Sur 11.7.5, watchOS 9.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted image may result in disclosure of process memory

This issue was addressed with improved checks

CVE-2023-23532 8.8 - High - May 08, 2023

This issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. An app may be able to break out of its sandbox

The issue was addressed with improved checks

CVE-2023-23527 5.5 - Medium - May 08, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.5, watchOS 9.4, macOS Ventura 13.3, tvOS 16.4, macOS Monterey 12.6.4. A user may gain access to protected parts of the file system

This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder

CVE-2023-23526 9.8 - Critical - May 08, 2023

This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A file from an iCloud shared-by-me folder may be able to bypass Gatekeeper

This issue was addressed with improved checks

CVE-2023-23525 7.8 - High - May 08, 2023

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to gain root privileges

A logic issue was addressed with improved restrictions

CVE-2023-23523 3.3 - Low - May 08, 2023

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup

An out-of-bounds read was addressed with improved bounds checking

CVE-2023-23528 6.5 - Medium - May 08, 2023

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted Bluetooth packet may result in disclosure of process memory

Out-of-bounds Read

A buffer overflow was addressed with improved bounds checking

CVE-2023-23494 5.3 - Medium - May 08, 2023

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to cause a denial-of-service

Classic Buffer Overflow

The issue was addressed with improved checks

CVE-2023-27942 5.5 - Medium - May 08, 2023

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, macOS Big Sur 11.7.5, watchOS 9.4, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4. An app may be able to access user-sensitive data

A validation issue was addressed with improved input sanitization

CVE-2023-27941 5.5 - Medium - May 08, 2023

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Big Sur 11.7.5, iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3. An app may be able to disclose kernel memory

An integer overflow was addressed with improved input validation

CVE-2023-27937 7.8 - High - May 08, 2023

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, macOS Big Sur 11.7.5, watchOS 9.4, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4. Parsing a maliciously crafted plist may lead to an unexpected app termination or arbitrary code execution

Integer Overflow or Wraparound

An out-of-bounds write issue was addressed with improved input validation

CVE-2023-27936 7.8 - High - May 08, 2023

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.7.5, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory

Memory Corruption

The issue was addressed with improved memory handling

CVE-2023-27959 7.8 - High - May 08, 2023

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

The issue was addressed with improved checks

CVE-2023-27955 5.5 - Medium - May 08, 2023

The issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.5, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. An app may be able to read arbitrary files

The issue was addressed by removing origin information

CVE-2023-27954 6.5 - Medium - May 08, 2023

The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. A website may be able to track sensitive user information

This issue was addressed with improved checks

CVE-2023-27943 5.5 - Medium - May 08, 2023

This issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Files downloaded from the internet may not have the quarantine flag applied

This issue was addressed by removing the vulnerable code

CVE-2023-27931 5.5 - Medium - May 08, 2023

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.3, tvOS 16.4, watchOS 9.4, macOS Big Sur 11.7.3, iOS 16.4 and iPadOS 16.4. An app may be able to access user-sensitive data

An out-of-bounds read was addressed with improved input validation

CVE-2023-27929 5.5 - Medium - May 08, 2023

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, macOS Ventura 13.3. Processing a maliciously crafted image may result in disclosure of process memory

Out-of-bounds Read

A validation issue was addressed with improved input sanitization

CVE-2023-28200 5.5 - Medium - May 08, 2023

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Big Sur 11.7.5, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3. An app may be able to disclose kernel memory

Improper Input Validation

The issue was addressed with improved memory handling

CVE-2023-28181 7.8 - High - May 08, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.7, macOS Ventura 13.3, tvOS 16.4, iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

Multiple validation issues were addressed with improved input sanitization

CVE-2023-27961 5.5 - Medium - May 08, 2023

Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Big Sur 11.7.5, watchOS 9.4, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4. Importing a maliciously crafted calendar invitation may exfiltrate user information

Improper Input Validation

An out-of-bounds read was addressed with improved input validation

CVE-2023-27949 7.8 - High - May 08, 2023

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution

Out-of-bounds Read

An out-of-bounds read was addressed with improved bounds checking

CVE-2023-27946 7.8 - High - May 08, 2023

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7.5, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution

Out-of-bounds Read

The issue was addressed with improved memory handling

CVE-2023-27933 6.7 - Medium - May 08, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4. An app with root privileges may be able to execute arbitrary code with kernel privileges

This issue was addressed with improved state management

CVE-2023-27932 5.5 - Medium - May 08, 2023

This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. Processing maliciously crafted web content may bypass Same Origin Policy

This issue was addressed with improved state management

CVE-2023-28201 9.8 - Critical - May 08, 2023

This issue was addressed with improved state management. This issue is fixed in Safari 16.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. A remote user may be able to cause unexpected app termination or arbitrary code execution

The issue was addressed with improved checks

CVE-2023-28194 3.3 - Low - May 08, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to unexpectedly create a bookmark on the Home Screen

A logic issue was addressed with improved validation

CVE-2023-28178 5.5 - Medium - May 08, 2023

A logic issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. An app may be able to bypass Privacy preferences

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2023-27970 7.8 - High - May 08, 2023

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

Memory Corruption

The issue was addressed with improved authentication

CVE-2023-28182 6.5 - Medium - May 08, 2023

The issue was addressed with improved authentication. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to spoof a VPN server that is configured with EAP-only authentication on a device

authentification

A use after free issue was addressed with improved memory management

CVE-2023-27969 7.8 - High - May 08, 2023

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

Dangling pointer

The issue was addressed with additional permissions checks

CVE-2023-27963 7.5 - High - May 08, 2023

The issue was addressed with additional permissions checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3, watchOS 9.4, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4. A shortcut may be able to use sensitive data with certain actions without prompting the user

The issue was addressed with improved memory handling

CVE-2023-27956 5.5 - Medium - May 08, 2023

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, macOS Ventura 13.3, tvOS 16.4, watchOS 9.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted image may result in disclosure of process memory

A privacy issue was addressed with improved private data redaction for log entries

CVE-2023-27928 3.3 - Low - May 08, 2023

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, macOS Big Sur 11.7.5, watchOS 9.4, iOS 16.4 and iPadOS 16.4. An app may be able to access information about a users contacts

The issue was addressed with additional restrictions on the observability of app states

CVE-2023-23543 3.6 - Low - May 08, 2023

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. A sandboxed app may be able to determine which app is currently using the camera

A privacy issue was addressed with improved private data redaction for log entries

CVE-2023-23541 3.3 - Low - May 08, 2023

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4. An app may be able to access information about a users contacts

The issue was addressed with improved memory handling

CVE-2023-23540 7.8 - High - May 08, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.5, macOS Monterey 12.6.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

A logic issue was addressed with improved restrictions

CVE-2022-46717 2.4 - Low - April 10, 2023

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2. A user with physical access to a locked Apple Watch may be able to view user photos via accessibility features

A logic issue was addressed with improved restrictions

CVE-2022-32871 2.4 - Low - April 10, 2023

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16. A person with physical access to a device may be able to use Siri to access private calendar information

A logic issue was addressed with improved restrictions

CVE-2022-46703 5.5 - Medium - April 10, 2023

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2. An app may be able to read sensitive location information

A use after free issue was addressed with improved memory management

CVE-2023-28205 8.8 - High - April 10, 2023

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3.1, iOS 16.4.1 and iPadOS 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, Safari 16.4.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Dangling pointer

An out-of-bounds write issue was addressed with improved input validation

CVE-2023-28206 8.6 - High - April 10, 2023

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6, macOS Ventura 13.3.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

Memory Corruption

A logic issue was addressed with improved state management

CVE-2022-46716 7.5 - High - April 10, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2. Private Relay functionality did not match system settings

A memory corruption issue was addressed with improved state management

CVE-2022-46709 9.8 - Critical - April 10, 2023

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able to execute arbitrary code with kernel privileges

Memory Corruption

A spoofing issue existed in the handling of URLs

CVE-2022-46705 4.3 - Medium - February 27, 2023

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.

Improper Input Validation

The issue was addressed with improved checks

CVE-2023-23496 8.8 - High - February 27, 2023

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.

A logic issue was addressed with improved state management

CVE-2023-23498 3.3 - Low - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, iOS 16.3 and iPadOS 16.3. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account.

This issue was addressed by enabling hardened runtime

CVE-2023-23499 5.5 - Medium - February 27, 2023

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. An app may be able to access user-sensitive data.

A logic issue was addressed with improved state management

CVE-2022-32855 5.5 - Medium - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen.

The issue was addressed with improved memory handling

CVE-2022-32824 5.5 - Medium - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to disclose kernel memory.

A logic issue was addressed with improved restrictions

CVE-2022-22668 5.5 - Medium - February 27, 2023

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A malicious application may be able to leak sensitive user information.

The issue was addressed with improved memory handling

CVE-2023-23504 7.8 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code with kernel privileges.

A logic issue was addressed with improved state management

CVE-2023-23503 5.5 - Medium - February 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.

The issue was addressed with improved handling of caches

CVE-2023-23512 6.5 - Medium - February 27, 2023

The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, iOS 16.3 and iPadOS 16.3, watchOS 9.3. Visiting a website may lead to an app denial-of-service.

The issue was addressed with improved memory handling

CVE-2023-23511 5.5 - Medium - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.

An out-of-bounds read issue was addressed with improved bounds checking

CVE-2022-32830 7.5 - High - February 27, 2023

An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.6, iOS 15.6 and iPadOS 15.6. Processing a maliciously crafted image may lead to disclosure of user information.

Out-of-bounds Read

The issue was addressed with improved memory handling

CVE-2023-23500 5.5 - Medium - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to leak sensitive kernel state.

The issue was addressed with improved UI handling

CVE-2022-32784 6.5 - Medium - February 27, 2023

The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and iPadOS 15.6. Visiting a maliciously crafted website may leak sensitive data.

A memory corruption issue was addressed with improved state management

CVE-2022-26760 9.8 - Critical - February 27, 2023

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-42826 8.8 - High - February 27, 2023

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

This issue was addressed with improved checks

CVE-2022-32949 7.8 - High - February 27, 2023

This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

A race condition was addressed with improved state handling

CVE-2022-32844 6.3 - Medium - February 27, 2023

A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication.

The issue was addressed with improved memory handling

CVE-2023-23531 8.6 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

The issue was addressed with improved memory handling

CVE-2023-23530 8.6 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

A type confusion issue was addressed with improved checks

CVE-2023-23529 8.8 - High - February 27, 2023

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Object Type Confusion

A denial-of-service issue was addressed with improved input validation

CVE-2023-23524 7.5 - High - February 27, 2023

A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1, tvOS 16.3.2, watchOS 9.3.1. Processing a maliciously crafted certificate may lead to a denial-of-service.

Resource Exhaustion

An information disclosure issue was addressed by removing the vulnerable code

CVE-2023-23502 5.5 - Medium - February 27, 2023

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to determine kernel memory layout.

The issue was addressed with improved UI handling

CVE-2022-32891 6.1 - Medium - February 27, 2023

The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.

Clickjacking

A privacy issue was addressed with improved private data redaction for log entries

CVE-2023-23505 3.3 - Low - February 27, 2023

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, iOS 15.7.3 and iPadOS 15.7.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. An app may be able to access information about a users contacts.

Insertion of Sensitive Information into Log File

A use after free issue was addressed with improved memory management

CVE-2023-23514 7.8 - High - February 27, 2023

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1. An app may be able to execute arbitrary code with kernel privileges..

Dangling pointer

The issue was addressed with improved memory handling

CVE-2023-23517 8.8 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. Processing maliciously crafted web content may lead to arbitrary code execution.

The issue was addressed with improved memory handling

CVE-2023-23518 8.8 - High - February 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3, tvOS 16.3, Safari 16.3, watchOS 9.3, iOS 16.3 and iPadOS 16.3, macOS Big Sur 11.7.3. Processing maliciously crafted web content may lead to arbitrary code execution.

A memory corruption issue was addressed with improved state management

CVE-2023-23519 7.5 - High - February 27, 2023

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, tvOS 16.3, iOS 16.3 and iPadOS 16.3, watchOS 9.3. Processing an image may lead to a denial-of-service.

Memory Corruption

A race condition was addressed with additional validation

CVE-2023-23520 5.9 - Medium - February 27, 2023

A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read arbitrary files as root.

TOCTTOU

An out-of-bounds write issue was addressed with improved input validation

CVE-2022-46693 7.8 - High - December 15, 2022

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.

Memory Corruption

An access issue existed with privileged API calls

CVE-2022-42849 7.8 - High - December 15, 2022

An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.

AuthZ

This issue was addressed with improved data protection

CVE-2022-42843 5.5 - Medium - December 15, 2022

This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.

Exposure of Resource to Wrong Sphere

The issue was addressed with improved memory handling

CVE-2022-42842 9.8 - Critical - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

An issue existed in the parsing of URLs

CVE-2022-42837 9.8 - Critical - December 15, 2022

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.

A logic issue was addressed with improved state management

CVE-2022-46692 5.5 - Medium - December 15, 2022

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.

A use after free issue was addressed with improved memory management

CVE-2022-42867 8.8 - High - December 15, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

The issue was addressed with improved handling of caches

CVE-2022-42866 5.5 - Medium - December 15, 2022

The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.

A memory corruption issue was addressed with improved state management

CVE-2022-42863 8.8 - High - December 15, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

The issue was addressed with improved memory handling

CVE-2022-42852 6.5 - Medium - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.

The issue was addressed with improved memory handling

CVE-2022-42846 5.5 - Medium - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.

The issue was addressed with improved memory handling

CVE-2022-42845 7.2 - High - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved memory handling

CVE-2022-42844 8.6 - High - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to break out of its sandbox.

The issue was addressed with improved memory handling

CVE-2022-42840 7.8 - High - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

An integer overflow was addressed with improved input validation

CVE-2022-42805 7.8 - High - December 15, 2022

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

Integer Overflow or Wraparound

A memory corruption issue was addressed with improved input validation

CVE-2022-46700 8.8 - High - December 15, 2022

A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A race condition was addressed with additional validation

CVE-2022-46689 7 - High - December 15, 2022

A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

Race Condition

The issue was addressed with improved bounds checks

CVE-2022-46701 7.8 - High - December 15, 2022

The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.

Buffer Overflow

This issue was addressed by enabling hardened runtime

CVE-2022-42865 5.5 - Medium - December 15, 2022

This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.

Multiple issues were addressed by removing the vulnerable code

CVE-2022-42859 5.5 - Medium - December 15, 2022

Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.

A type confusion issue was addressed with improved state handling

CVE-2022-42856 8.8 - High - December 15, 2022

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..

Object Type Confusion

The issue was addressed with improved memory handling

CVE-2022-46702 5.5 - Medium - December 15, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to disclose kernel memory.

A memory corruption issue was addressed with improved state management

CVE-2022-46699 8.8 - High - December 15, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple Safari or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple iOS
The iOS Operating System used by iPhones.

subscribe