cd ../exploit-db
root@mhfh:~#ls -la /var/db/exploits/ios/
ios_exploit_db.json
🍎 iPhone Exploit DB
Curated iOS / iPadOS / Safari vulnerabilities — WebKit RCEs, kernel LPEs, ImageIO 0-clicks. Each entry links to a full technical writeup with PoC and downloads.
7
total
6
crit
1
high
0
med
ios-exploit-db.sh --query
$ severity:
$ type:
$ sort:
CVE-2026-20640High
iPhone Mirroring UI state disclosure
type: InfoLeakaffected: < 26.3date: 2026-02-13
$ cat /var/db/exploits/CVE-2026-20640.json →
CVE-2026-20700Critical
Memory corruption arbitrary code execution
type: RCEaffected: < 26.3date: 2026-02-11
$ cat /var/db/exploits/CVE-2026-20700.json →
CVE-2025-43529Critical
WebKit Use-After-Free arbitrary code
type: RCEaffected: < 26.2date: 2025-12-15
$ cat /var/db/exploits/CVE-2025-43529.json →
CVE-2024-44308Critical
JavaScriptCore UXSS chain
type: RCEaffected: ≤18.1date: 2024-11-19
$ cat /var/db/exploits/CVE-2024-44308.json →
CVE-2024-23222Critical
WebKit RCE via type confusion
type: RCEaffected: ≤17.3date: 2024-01-22
$ cat /var/db/exploits/CVE-2024-23222.json →
CVE-2023-41064Critical
BLASTPASS ImageIO 0-click
type: 0-clickaffected: ≤16.6date: 2023-09-07
$ cat /var/db/exploits/CVE-2023-41064.json →
CVE-2022-32893Critical
WebKit OOB write → kernel LPE
type: LPEaffected: ≤15.6date: 2022-08-17
$ cat /var/db/exploits/CVE-2022-32893.json →
7 of 7 record(s)