Apple Safari
30 known vulnerabilities in Apple Safari, 1 critical, 22 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2025-43529 CVSS 8.8 high · actively exploited Apple Multiple Products Use-After-Free WebKit Vulnerability
- CVE-2023-43000 CVSS 8.8 high · actively exploited Apple Multiple products Use-After-Free Vulnerability
- CVE-2025-31277 CVSS 8.8 high · actively exploited Apple Multiple Products Buffer Overflow Vulnerability
- CVE-2025-24201 CVSS 10.0 critical · actively exploited Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
- CVE-2024-44309 CVSS 6.3 medium · actively exploited Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
- CVE-2024-44308 CVSS 8.8 high · actively exploited Apple Multiple Products Code Execution Vulnerability
- CVE-2024-23222 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Type Confusion Vulnerability
- CVE-2023-42917 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Memory Corruption Vulnerability
- CVE-2023-42916 CVSS 6.5 medium · actively exploited Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
- CVE-2022-48503 CVSS 8.8 high · actively exploited Apple Multiple Products Unspecified Vulnerability
Latest vulnerabilities
- CVE-2026-86898 CVSS 5.4 medium A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27…
- CVE-2026-86897 CVSS 5.5 medium This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS…
- CVE-2026-84635 CVSS 6.5 medium A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27…
- CVE-2026-84518 CVSS 4.3 medium This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27…
- CVE-2026-65391 CVSS 8.8 high An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS…
- CVE-2026-65390 CVSS 8.8 high An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1…
- CVE-2026-64753 CVSS 6.5 medium A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden…
- CVE-2026-64715 CVSS 6.5 medium A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS…
- CVE-2025-43529 CVSS 8.8 high · actively exploited Apple Multiple Products Use-After-Free WebKit Vulnerability
- CVE-2023-43000 CVSS 8.8 high · actively exploited Apple Multiple products Use-After-Free Vulnerability
- CVE-2025-31277 CVSS 8.8 high · actively exploited Apple Multiple Products Buffer Overflow Vulnerability
- CVE-2025-24201 CVSS 10.0 critical · actively exploited Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
- CVE-2024-44309 CVSS 6.3 medium · actively exploited Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
- CVE-2024-44308 CVSS 8.8 high · actively exploited Apple Multiple Products Code Execution Vulnerability
- CVE-2024-23222 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Type Confusion Vulnerability
- CVE-2023-42917 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Memory Corruption Vulnerability
- CVE-2023-42916 CVSS 6.5 medium · actively exploited Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
- CVE-2022-48503 CVSS 8.8 high · actively exploited Apple Multiple Products Unspecified Vulnerability
- CVE-2023-37450 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Code Execution Vulnerability
- CVE-2023-32439 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Type Confusion Vulnerability
- CVE-2023-32435 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Memory Corruption Vulnerability
- CVE-2023-32409 CVSS 8.6 high · actively exploited Apple Multiple Products WebKit Sandbox Escape Vulnerability
- CVE-2023-32373 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Use-After-Free Vulnerability
- CVE-2023-28204 CVSS 6.5 medium · actively exploited Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
- CVE-2023-28205 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Use-After-Free Vulnerability
- CVE-2023-23529 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Type Confusion Vulnerability
- CVE-2022-32893 CVSS 8.8 high · actively exploited Apple iOS and macOS Out-of-Bounds Write Vulnerability
- CVE-2022-22620 CVSS 8.8 high · actively exploited Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability
- CVE-2021-30661 CVSS 8.8 high · actively exploited Apple Multiple Products WebKit Storage Use-After-Free Vulnerability
- CVE-2019-8506 CVSS 8.8 high · actively exploited Apple Multiple Products Type Confusion Vulnerability