📦 Safari

by Apple

🔍 What is Safari?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-43526

CRITICAL CVSS 9.8 Dec 17, 2025

A URL validation vulnerability in macOS and Safari allows web content opened via file URLs to bypass Lockdown Mode restrictions and access Web APIs that should be blocked. This affects macOS users wit...

CVE-2025-43342

CRITICAL CVSS 9.8 Sep 15, 2025

This vulnerability in Apple's Safari browser and related operating systems allows processing malicious web content to cause unexpected process crashes. It affects users of Safari, iOS, iPadOS, tvOS, w...

CVE-2025-30466

CRITICAL CVSS 9.8 May 29, 2025

This vulnerability allows malicious websites to bypass the Same Origin Policy in Apple's Safari browser and related WebKit-based browsers. This could enable cross-site data theft or session hijacking....

CVE-2025-24167

CRITICAL CVSS 9.8 Mar 31, 2025

This vulnerability in Apple's Safari browser and related operating systems allows attackers to misrepresent a download's origin, potentially tricking users into executing malicious files. It affects S...

CVE-2025-24201

CRITICAL CVSS 10.0 Mar 11, 2025

This critical vulnerability allows malicious web content to break out of the Web Content sandbox via an out-of-bounds write issue, potentially enabling arbitrary code execution. It affects Apple devic...

CVE-2024-54542

CRITICAL CVSS 9.1 Jan 27, 2025

This CVE describes an authentication bypass vulnerability in Apple's Private Browsing feature across multiple platforms. Attackers could access Private Browsing tabs without proper authentication, pot...

CVE-2024-54534

CRITICAL CVSS 9.8 Dec 12, 2024

This is a critical memory corruption vulnerability in Apple's WebKit browser engine that affects multiple Apple operating systems and Safari. Processing malicious web content could allow attackers to ...

CVE-2024-44206

CRITICAL CVSS 9.3 Oct 24, 2024

This vulnerability allows users to bypass web content restrictions through improper URL protocol handling in Apple operating systems and Safari. It affects users running vulnerable versions of tvOS, v...

CVE-2024-4558

CRITICAL CVSS 9.6 May 7, 2024

This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. It allows remote attackers to potentially exploit heap corruption via crafted HTML pag...

CVE-2023-40414

CRITICAL CVSS 9.8 Jan 10, 2024

This is a critical use-after-free vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content. It affects all Apple devices running outdat...

CVE-2023-28201

CRITICAL CVSS 9.8 May 8, 2023

This vulnerability allows a remote attacker to cause unexpected app termination or execute arbitrary code on affected Apple devices. It affects macOS, iOS, iPadOS, tvOS, and Safari users who haven't u...

CVE-2020-9895

CRITICAL CVSS 9.8 Oct 16, 2020

This is a critical use-after-free memory corruption vulnerability in Apple's iOS, iPadOS, tvOS, watchOS, Safari, iTunes, and iCloud for Windows. A remote attacker could exploit this to crash applicati...

CVE-2026-20652

HIGH CVSS 7.5 Feb 11, 2026

This CVE describes a memory handling vulnerability in Apple operating systems and Safari that could allow a remote attacker to cause denial-of-service. The issue affects macOS, iOS, iPadOS, visionOS, ...

CVE-2026-20660

HIGH CVSS 7.5 Feb 11, 2026

This CVE describes a path handling vulnerability (CWE-22) in multiple Apple operating systems and Safari that allows a remote attacker to write arbitrary files to affected systems. The vulnerability a...

CVE-2025-43529

HIGH CVSS 8.8 Dec 17, 2025

A use-after-free vulnerability in Apple's WebKit browser engine allows processing malicious web content to execute arbitrary code. This affects multiple Apple operating systems and Safari browser vers...

CVE-2025-14174

HIGH CVSS 8.8 Dec 12, 2025

This vulnerability allows remote attackers to perform out-of-bounds memory access in ANGLE (Almost Native Graphics Layer Engine) in Google Chrome on macOS. Attackers can exploit this by tricking users...

CVE-2023-43000

HIGH CVSS 8.8 Nov 5, 2025

A use-after-free vulnerability in Apple's WebKit browser engine allows memory corruption when processing malicious web content. This affects users of macOS, iOS, iPadOS, and Safari who visit compromis...

CVE-2025-43502

HIGH CVSS 7.5 Nov 4, 2025

This CVE describes a privacy bypass vulnerability in Apple operating systems where applications can circumvent certain privacy preferences, potentially accessing sensitive data they shouldn't. It affe...

CVE-2025-43413

HIGH CVSS 7.5 Nov 4, 2025

This vulnerability allows sandboxed applications on Apple operating systems to observe system-wide network connections, potentially exposing sensitive network traffic information. It affects multiple ...

CVE-2025-43376

HIGH CVSS 7.5 Nov 4, 2025

This vulnerability allows remote attackers to view leaked DNS queries when Apple's Private Relay feature is enabled. It affects users of Safari, iOS, iPadOS, tvOS, watchOS, and visionOS with Private R...

CVE-2025-43227

HIGH CVSS 7.5 Jul 30, 2025

This vulnerability in Apple's WebKit browser engine allows malicious web content to bypass security controls and access sensitive user information. It affects Safari and all Apple operating systems th...

CVE-2025-31273

HIGH CVSS 8.8 Jul 30, 2025

This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malicious websites. It affects Safari and all Apple ope...

CVE-2025-31277

HIGH CVSS 8.8 Jul 30, 2025

This is a memory corruption vulnerability in Apple's WebKit browser engine affecting multiple Apple operating systems. Processing malicious web content could allow attackers to execute arbitrary code ...

CVE-2025-6558

HIGH CVSS 8.8 Jul 15, 2025

This vulnerability in Google Chrome's ANGLE and GPU components allows insufficient input validation, enabling a remote attacker to potentially escape the browser sandbox via a malicious HTML page. All...

CVE-2025-24189

HIGH CVSS 8.8 May 19, 2025

This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malicious websites. It affects Safari and all Apple ope...

CVE-2025-31223

HIGH CVSS 8.0 May 12, 2025

This memory corruption vulnerability in Apple's WebKit browser engine allows attackers to execute arbitrary code by tricking users into visiting malicious websites. It affects all Apple devices runnin...

CVE-2025-31204

HIGH CVSS 8.8 May 12, 2025

This is a memory corruption vulnerability in Apple's WebKit browser engine affecting multiple Apple operating systems and Safari. Processing malicious web content could allow attackers to execute arbi...

CVE-2025-24223

HIGH CVSS 8.0 May 12, 2025

This is a cross-site request forgery (CSRF) vulnerability in Apple's WebKit browser engine that could allow memory corruption when processing malicious web content. It affects users of Apple devices a...

CVE-2023-42970

HIGH CVSS 8.8 Apr 11, 2025

This CVE describes a use-after-free vulnerability in Apple's WebKit browser engine that could allow arbitrary code execution when processing malicious web content. It affects multiple Apple operating ...

CVE-2025-31184

HIGH CVSS 7.8 Mar 31, 2025

This vulnerability allows malicious applications to bypass permission checks and gain unauthorized access to the local network on Apple devices. It affects Safari browsers and Apple operating systems ...

CVE-2025-24213

HIGH CVSS 7.8 Mar 31, 2025

A type confusion vulnerability in Apple's WebKit browser engine could allow memory corruption when processing floating-point numbers. This affects users of Apple devices running vulnerable versions of...

CVE-2025-24209

HIGH CVSS 7.0 Mar 31, 2025

This CVE describes a buffer overflow vulnerability in Apple's web content processing components. Attackers can cause unexpected process crashes by tricking users into visiting malicious websites. Affe...

CVE-2024-54551

HIGH CVSS 7.5 Mar 21, 2025

This memory handling vulnerability in Apple's web content processing allows attackers to cause denial-of-service conditions. It affects users of Apple devices and software that process web content, in...

CVE-2025-24169

HIGH CVSS 7.5 Jan 27, 2025

This vulnerability allows malicious applications to bypass browser extension authentication in Safari by exploiting a logging issue that exposes sensitive data. It affects macOS users running vulnerab...

CVE-2025-24150

HIGH CVSS 8.8 Jan 27, 2025

This vulnerability allows command injection when copying URLs from Web Inspector in affected Apple products. Attackers could execute arbitrary commands on the system by tricking users into copying mal...

CVE-2024-27856

HIGH CVSS 7.8 Jan 15, 2025

This vulnerability allows processing a malicious file to cause unexpected app termination or arbitrary code execution on affected Apple devices. It affects macOS, iOS, iPadOS, Safari, watchOS, tvOS, a...

CVE-2024-54505

HIGH CVSS 8.8 Dec 12, 2024

This CVE describes a type confusion vulnerability in Apple's WebKit browser engine that could allow memory corruption when processing malicious web content. Attackers could exploit this to execute arb...

CVE-2024-54479

HIGH CVSS 7.5 Dec 12, 2024

This vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. It affects users of Safari browser and Apple operating systems includin...

CVE-2024-44259

HIGH CVSS 7.5 Oct 28, 2024

This vulnerability allows an attacker to exploit a trust relationship to download malicious content onto Apple devices. It affects iOS, iPadOS, visionOS, macOS, and Safari users running vulnerable ver...

CVE-2024-27833

HIGH CVSS 8.8 Jun 10, 2024

This CVE describes an integer overflow vulnerability in Apple's WebKit browser engine that could allow arbitrary code execution when processing malicious web content. It affects multiple Apple operati...

CVE-2024-27851

HIGH CVSS 8.8 Jun 10, 2024

This is a memory corruption vulnerability in Apple's WebKit browser engine, allowing arbitrary code execution when processing malicious web content. It affects multiple Apple operating systems and Saf...

CVE-2024-27808

HIGH CVSS 8.8 Jun 10, 2024

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to execute arbitrary code on affected devices. It affects users of Apple's operating systems...

CVE-2024-27820

HIGH CVSS 8.8 Jun 10, 2024

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to execute arbitrary code on affected devices. It affects users of Apple's operating systems...

CVE-2023-42866

HIGH CVSS 8.8 Jan 10, 2024

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to execute arbitrary code on affected devices. It affects macOS, iOS, iPadOS, tvOS, Safari, ...

CVE-2023-42917

HIGH CVSS 8.8 Nov 30, 2023

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content. It affects iOS, iPadOS, macOS, and Safari users r...

CVE-2023-42852

HIGH CVSS 8.8 Oct 25, 2023

This is a logic vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content. Attackers can exploit this by tricking users into visiting sp...

CVE-2023-41976

HIGH CVSS 8.8 Oct 25, 2023

This CVE describes a use-after-free vulnerability in Apple's web content processing components that could allow arbitrary code execution when visiting malicious websites. It affects multiple Apple ope...

CVE-2023-41074

HIGH CVSS 8.8 Sep 27, 2023

This vulnerability allows arbitrary code execution when processing malicious web content in Apple's WebKit browser engine. It affects users of Safari and Apple operating systems before the 2023 update...

CVE-2023-40451

HIGH CVSS 8.8 Sep 27, 2023

This vulnerability in Safari's iframe sandbox enforcement allows attackers with JavaScript execution to bypass security restrictions and execute arbitrary code. It affects Safari users on macOS and iO...

CVE-2022-48503

HIGH CVSS 8.8 Aug 14, 2023

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content. Attackers can exploit this by tricking users into...

CVE-2023-38611

HIGH CVSS 8.8 Jul 27, 2023

This is a memory corruption vulnerability in Apple's WebKit browser engine that allows arbitrary code execution when processing malicious web content. It affects iOS, iPadOS, tvOS, macOS, Safari, and ...

CVE-2023-38595

HIGH CVSS 8.8 Jul 27, 2023

This vulnerability allows arbitrary code execution when processing malicious web content. It affects Apple devices running vulnerable versions of iOS, iPadOS, tvOS, macOS, Safari, and watchOS. Attacke...

CVE-2026-20676

MEDIUM CVSS 5.3 Feb 11, 2026

This vulnerability allows malicious websites to track users through Safari web extensions due to improper state management. It affects users of Apple's Safari browser across multiple Apple operating s...

CVE-2026-20644

MEDIUM CVSS 6.5 Feb 11, 2026

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. It affects users of macOS, iOS, iPadOS, visionOS, and S...

CVE-2026-20635

MEDIUM CVSS 4.3 Feb 11, 2026

This CVE describes a memory handling vulnerability in Apple's WebKit browser engine that affects multiple Apple operating systems and Safari. Processing malicious web content could cause unexpected pr...

CVE-2026-20636

MEDIUM CVSS 6.5 Feb 11, 2026

This memory handling vulnerability in Apple's WebKit browser engine allows processing malicious web content to cause unexpected process crashes. It affects users of iOS, iPadOS, Safari, macOS, and vis...

CVE-2026-20608

MEDIUM CVSS 5.5 Feb 11, 2026

This CVE describes a memory management vulnerability in Apple's WebKit browser engine that could cause unexpected process crashes when processing malicious web content. It affects multiple Apple opera...

CVE-2025-46282

MEDIUM CVSS 5.5 Dec 17, 2025

This CVE describes a macOS and Safari vulnerability where insufficient permission checks could allow an application to access sensitive user data. The issue affects macOS Tahoe and Safari versions bef...

CVE-2025-43535

MEDIUM CVSS 4.3 Dec 17, 2025

This CVE describes a memory handling vulnerability in Apple's Safari browser and related operating systems. Processing malicious web content could cause an unexpected process crash (denial of service)...

CVE-2025-43536

MEDIUM CVSS 4.3 Dec 17, 2025

A use-after-free vulnerability in Apple's web content processing allows attackers to cause unexpected process crashes by tricking users into visiting malicious websites. This affects macOS, iOS, iPadO...

CVE-2025-43541

MEDIUM CVSS 4.3 Dec 17, 2025

A type confusion vulnerability in Apple's Safari browser and related operating systems could cause unexpected crashes when processing malicious web content. This affects users running vulnerable versi...

CVE-2025-43501

MEDIUM CVSS 4.3 Dec 17, 2025

A buffer overflow vulnerability in Apple's Safari browser and related operating systems allows attackers to cause unexpected process crashes by tricking users into visiting malicious websites. This af...

CVE-2025-43503

MEDIUM CVSS 4.3 Nov 4, 2025

This CVE describes a user interface spoofing vulnerability in Apple operating systems and Safari browser. Visiting a malicious website could allow attackers to present fake interface elements, potenti...

CVE-2025-43493

MEDIUM CVSS 4.3 Nov 4, 2025

This CVE describes an address bar spoofing vulnerability in Apple web browsers. Visiting a malicious website could allow attackers to display a fake URL in the address bar, tricking users into thinkin...

CVE-2025-43392

MEDIUM CVSS 4.3 Nov 4, 2025

This vulnerability allows malicious websites to bypass same-origin policy protections and exfiltrate image data from other websites. It affects users of Apple's Safari browser and operating systems wi...

CVE-2025-43368

MEDIUM CVSS 4.3 Sep 15, 2025

A use-after-free vulnerability in Apple Safari, iOS, and iPadOS allows processing malicious web content to cause unexpected crashes. This affects users running vulnerable versions of these Apple produ...

CVE-2025-43356

MEDIUM CVSS 6.5 Sep 15, 2025

This vulnerability allows malicious websites to access device sensor data (like motion, orientation, or environmental sensors) without obtaining user permission. It affects Apple devices running vulne...

CVE-2025-43327

MEDIUM CVSS 6.5 Sep 15, 2025

This Safari vulnerability allows malicious websites to spoof the address bar, making users believe they're on a legitimate site when they're actually on an attacker-controlled page. It affects Safari ...

CVE-2025-31254

MEDIUM CVSS 5.4 Sep 15, 2025

This Safari/iOS/iPadOS vulnerability allows malicious web content to trigger unexpected URL redirections due to improper URL validation. It affects users of Apple's Safari browser and iOS/iPadOS devic...

CVE-2025-43229

MEDIUM CVSS 6.1 Jul 30, 2025

This vulnerability allows attackers to execute universal cross-site scripting (XSS) attacks by processing malicious web content. It affects macOS and Safari users who haven't updated to patched versio...

CVE-2025-43240

MEDIUM CVSS 6.2 Jul 30, 2025

This CVE describes a logic flaw in macOS and Safari where a download's origin may be incorrectly associated, potentially allowing malicious downloads to appear legitimate. It affects macOS users befor...

CVE-2025-43212

MEDIUM CVSS 6.5 Jul 30, 2025

A memory handling vulnerability in Apple WebKit (CWE-119) allows malicious web content to cause Safari to crash unexpectedly. This affects users of Safari and Apple operating systems before the patche...

CVE-2025-43214

MEDIUM CVSS 6.5 Jul 30, 2025

This CVE describes a memory handling vulnerability in Apple's Safari browser and related WebKit components across multiple Apple operating systems. Processing malicious web content could cause Safari ...

CVE-2025-43216

MEDIUM CVSS 6.5 Jul 30, 2025

A use-after-free vulnerability in Apple's Safari browser and related WebKit components allows attackers to cause unexpected crashes by processing malicious web content. This affects users of Safari on...

CVE-2025-24188

MEDIUM CVSS 6.5 Jul 30, 2025

This CVE describes a logic flaw in Safari that could be exploited by malicious web content to cause unexpected crashes. The vulnerability affects Safari users on macOS, potentially leading to denial o...

CVE-2025-31257

MEDIUM CVSS 4.7 May 12, 2025

This CVE describes a memory handling vulnerability in Apple's WebKit browser engine that could cause Safari to crash when processing malicious web content. It affects multiple Apple operating systems ...

CVE-2025-31215

MEDIUM CVSS 6.5 May 12, 2025

This vulnerability allows malicious web content to cause unexpected process crashes in Apple's Safari browser and operating systems. It affects users running outdated versions of watchOS, tvOS, iPadOS...

CVE-2025-31206

MEDIUM CVSS 4.3 May 12, 2025

A type confusion vulnerability in Apple's Safari browser and related operating systems could cause unexpected crashes when processing malicious web content. This affects users of Safari 18.5 and earli...

CVE-2025-24216

MEDIUM CVSS 4.3 Mar 31, 2025

This CVE describes a memory handling vulnerability in Apple's Safari browser and related operating systems. Processing malicious web content could cause Safari to crash unexpectedly. Users of affected...

CVE-2025-24192

MEDIUM CVSS 6.5 Mar 31, 2025

A script imports isolation vulnerability in Apple WebKit allows malicious websites to bypass security boundaries and access sensitive data from other websites or browser sessions. This affects users o...

CVE-2024-44192

MEDIUM CVSS 5.5 Mar 10, 2025

This vulnerability allows malicious web content to cause unexpected process crashes in Apple's WebKit browser engine. It affects users of Safari and Apple operating systems with vulnerable versions. T...

CVE-2025-24162

MEDIUM CVSS 6.5 Jan 27, 2025

This vulnerability is an out-of-bounds read (CWE-125) in Apple's WebKit browser engine that could cause unexpected process crashes when processing malicious web content. It affects multiple Apple oper...

CVE-2026-20656

LOW CVSS 3.3 Feb 11, 2026

A logic vulnerability in Apple's iOS, iPadOS, Safari, and macOS allows malicious applications to access a user's Safari browsing history without proper authorization. This affects users running outdat...

CVE-2025-43531

LOW CVSS 3.1 Dec 17, 2025

This CVE describes a race condition vulnerability in Apple's web content processing that could allow an attacker to cause unexpected process crashes. It affects multiple Apple operating systems and Sa...