Iphone Os

Vendor:

First CVE: Jun 25, 2007 · Active for 19 years

4,511
Total CVEs
More Total CVEs than 100% of tracked products
225.6
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
2.1%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Iphone Os over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2007
19 years ago
Most Recent CVE
Jul 14, 2026
11 days ago

CVE Severity & Scoring

Iphone Os4,511 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local1,526 (33.8%)
Network1,740 (38.6%)
Unknown1,056 (23.4%)
Physical144 (3.2%)
Adjacent Network45 (1.0%)
Attack Complexity
Low3,303 (73.2%)
High152 (3.4%)
Unknown1,056 (23.4%)
User Interaction
None1,124 (24.9%)
Unknown1,056 (23.4%)
Required2,331 (51.7%)
Privileges Required
Low381 (8.4%)
High26 (0.6%)
None3,048 (67.6%)
Unknown1,056 (23.4%)

Top CVEs

Signals from CVEs in this product scope (4511 CVEs).

4,511 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Aug 25, 20168.895YESYES
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0
Feb 10, 20168.892YESYES
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adob
Dec 28, 20158.892YESNO
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that pro
Sep 18, 20147.892YESYES
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Jul 28, 20228.891YESNO
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.
Aug 24, 20217.891YESNO
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adob
Oct 15, 20149.391NOYES
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra
Sep 28, 20238.887YESNO
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
Aug 25, 20167.887YESYES
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS
Jan 27, 202510.086YESYES

Exploit Exposure

Signals from CVEs in this product scope (4511 CVEs).

CISA KEV
96 CVEs
2.1% of CVEs· 96th percentile
Metasploit
19 CVEs
0.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
290 CVEs
6.4% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (4511 CVEs).

Media Mentions

Signals from CVEs in this product scope (4511 CVEs).

Top CNAs Publishing CVEs For Iphone Os

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3.517.51.0%00
9.3.417.51.0%00
9.3.327.71.2%00
9.3.217.51.0%00
9.3.117.51.0%00
9.317.51.0%00
9.2.117.51.0%00
9.217.51.0%00
9.117.51.0%00
9.0.217.51.0%00
9.0.117.51.0%00
9.017.51.0%00
8.4.117.51.0%00
8.317.85.5%00
8.227.73.3%00
8.1.327.73.3%00
8.1.227.73.3%00
8.127.73.3%00
8.0.296.01.9%00
8.0.196.01.9%00