cd ../exploit-db
root@mhfh:~#ls -la /var/db/exploits/ios/
ios_exploit_db.json
🍎 iPhone Exploit DB
Curated iOS / iPadOS / Safari vulnerabilities, WebKit RCEs, kernel LPEs, ImageIO 0-clicks. Each entry links to a full technical writeup with PoC and downloads.
11
total
8
crit
3
high
0
med
ios-exploit-db.sh --query
$ severity:
$ type:
$ sort:
CVE-2026-43722High
Kernel sensitive-state information disclosure
type: InfoLeakaffected: iOS/iPadOS < 26.5.2date: 2026-06-29status: Vendor confirmed
$ cat /var/db/exploits/CVE-2026-43722.json →
CVE-2026-20640High
iPhone Mirroring UI state disclosure
type: InfoLeakaffected: < 26.3date: 2026-02-13status: Publicly disclosed
$ cat /var/db/exploits/CVE-2026-20640.json →
CVE-2026-20700Critical
Memory corruption arbitrary code execution
type: RCEaffected: < 26.3date: 2026-02-11status: Publicly disclosed
$ cat /var/db/exploits/CVE-2026-20700.json →
CVE-2025-43529Critical
WebKit Use-After-Free arbitrary code
type: RCEaffected: < 26.2date: 2025-12-15status: Publicly disclosed
$ cat /var/db/exploits/CVE-2025-43529.json →
CVE-2025-14174Critical
WebKit memory corruption in targeted attacks
type: RCEaffected: iOS versions before iOS 26date: 2025-12-12status: Exploited in the wild
$ cat /var/db/exploits/CVE-2025-14174.json →
CVE-2025-31200Critical
CoreAudio crafted-media code execution
type: RCEaffected: iOS/iPadOS < 18.4.1date: 2025-04-16status: Exploited in the wild
$ cat /var/db/exploits/CVE-2025-31200.json →
CVE-2025-31201High
RPAC Pointer Authentication bypass
type: Sandboxaffected: iOS/iPadOS < 18.4.1date: 2025-04-16status: Exploited in the wild
$ cat /var/db/exploits/CVE-2025-31201.json →
CVE-2024-44308Critical
JavaScriptCore UXSS chain
type: RCEaffected: ≤18.1date: 2024-11-19status: Publicly disclosed
$ cat /var/db/exploits/CVE-2024-44308.json →
CVE-2024-23222Critical
WebKit RCE via type confusion
type: RCEaffected: ≤17.3date: 2024-01-22status: Publicly disclosed
$ cat /var/db/exploits/CVE-2024-23222.json →
CVE-2023-41064Critical
BLASTPASS ImageIO 0-click
type: 0-clickaffected: ≤16.6date: 2023-09-07status: Publicly disclosed
$ cat /var/db/exploits/CVE-2023-41064.json →
CVE-2022-32893Critical
WebKit OOB write → kernel LPE
type: LPEaffected: ≤15.6date: 2022-08-17status: Publicly disclosed
$ cat /var/db/exploits/CVE-2022-32893.json →
11 of 11 record(s)