CVE-2025-43219
published 2026-04-02CVE-2025-43219: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.43%
34.6th percentile
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 15.6 | 15.6 |
| apple | macos_sequoia | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43219: macOS Sequoia 15.6
vendor_apple·2025-07-29·CVSS 8.8
CVE-2025-43219 [HIGH] CVE-2025-43219: macOS Sequoia 15.6
Apple Security Update: About the security content of macOS Sequoia 15.6
Product: macOS Sequoia
Version: 15.6
CVE: CVE-2025-43219
Component: Model I/O
Impact: Processing a maliciously crafted image may corrupt process memory
Description: The issue was addressed with improved memory handling.
GHSA
GHSA-p5fv-r355-w43j: The issue was addressed with improved memory handling
ghsa_unreviewed·2026-04-02
CVE-2025-43219 [HIGH] CWE-787 GHSA-p5fv-r355-w43j: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-46290 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46290 [HIGH] CVE-2025-46290 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46290 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. A remote attacker may be able to cause a denial-of-service.
Source : NVD
## 7.5
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Security
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus
Wiz
CVE-2026-20610 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20610 [HIGH] CVE-2026-20610 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20610 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Setup Assistant
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Co
Wiz
CVE-2024-44303 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2024-44303 [HIGH] CVE-2024-44303 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-44303 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the file system.
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 24.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
PackageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Wiz
CVE-2026-28839 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28839 [HIGH] CVE-2026-28839 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28839 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NetAuth
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severit
Wiz
CVE-2026-28878 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28878 [HIGH] CVE-2026-28878 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28878 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Crash Reporter
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on
Wiz
CVE-2025-43393 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43393 [HIGH] CVE-2025-43393 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43393 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of its sandbox.
Source : NVD
## 5.2
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
quarantine
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Tech
Wiz
CVE-2026-20701 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20701 [HIGH] CVE-2026-20701 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20701 :
macOS vulnerability analysis and mitigation
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
NetAuth
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related
Wiz
CVE-2026-20654 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20654 [HIGH] CVE-2026-20654 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20654 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Relate
Wiz
CVE-2026-20627 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20627 [HIGH] CVE-2026-20627 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20627 :
macOS vulnerability analysis and mitigation
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can fo
Wiz
CVE-2025-43508 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43508 [HIGH] CVE-2025-43508 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43508 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published January 16, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Phone
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Compon
Wiz
CVE-2025-46289 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46289 [HIGH] CVE-2025-46289 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46289 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppSandbox
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2026-28886 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28886 [HIGH] CVE-2026-28886 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28886 :
macOS vulnerability analysis and mitigation
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A user in a privileged network position may be able to cause a denial-of-service.
Source : NVD
## 5.9
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
CoreUtils
Sources
NVD
## Get a CVE risk assessment
Get a
Wiz
CVE-2025-43471 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43471 [HIGH] CVE-2025-43471 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43471 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Admin Framework
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component n
Wiz
CVE-2025-46310 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46310 [HIGH] CVE-2025-46310 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46310 :
macOS vulnerability analysis and mitigation
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4. An attacker with root privileges may be able to delete protected system files.
Source : NVD
## 6
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
PackageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulner
Wiz
CVE-2025-46291 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46291 [HIGH] CVE-2025-46291 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46291 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.
Source : NVD
## 7.8
Score
Published December 17, 2025
Severity HIGH
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
LaunchServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
C
Wiz
CVE-2026-20630 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20630 [HIGH] CVE-2026-20630 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20630 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
LaunchServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Techno
Wiz
CVE-2025-43403 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43403 [HIGH] CVE-2025-43403 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43403 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Compression
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE
Wiz
CVE-2025-43532 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43532 [HIGH] CVE-2025-43532 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43532 :
macOS vulnerability analysis and mitigation
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malicious data may lead to unexpected app termination.
Source : NVD
## 2.8
Score
Published December 12, 2025
Severity LOW
CNA Score 2.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Foundation
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view
Wiz
CVE-2025-43470 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43470 [HIGH] CVE-2025-43470 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43470 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. A standard user may be able to view files made from a disk image belonging to an administrator.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Disk Images
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnera
Wiz
CVE-2025-46283 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46283 [HIGH] CVE-2025-46283 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46283 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 17, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Scor
Wiz
CVE-2025-46278 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46278 [HIGH] CVE-2025-46278 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46278 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published December 17, 2025
Severity MEDIUM
CNA Score 5.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Game Center
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
C
Wiz
CVE-2026-20602 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20602 [HIGH] CVE-2026-20602 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20602 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to cause a denial-of-service.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
WindowServer
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2025-43404 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43404 [HIGH] CVE-2025-43404 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43404 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 3.3
Score
Published December 12, 2025
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Sandbox
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technolo
Wiz
CVE-2026-28832 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28832 [HIGH] CVE-2026-28832 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28832 :
macOS vulnerability analysis and mitigation
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to disclose kernel memory.
Source : NVD
## 8.4
Score
Published March 25, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
File System
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2026-20670 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20670 [HIGH] CVE-2026-20670 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20670 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleEvents
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Sev
Wiz
CVE-2025-46279 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46279 [HIGH] CVE-2025-46279 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46279 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.
Source : NVD
## 3.3
Score
Published December 17, 2025
Severity LOW
CNA Score 9.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Icons
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exp
Wiz
CVE-2024-44238 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2024-44238 [HIGH] CVE-2024-44238 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-44238 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to corrupt coprocessor memory.
Source : NVD
## 7.8
Score
Published January 16, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
IOMobileFrameBuffer
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Seve
Wiz
CVE-2026-28855 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28855 [HIGH] CVE-2026-28855 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28855 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access protected user data.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Screen Time
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Seve
Wiz
CVE-2026-20680 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20680 [HIGH] CVE-2026-20680 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20680 :
macOS vulnerability analysis and mitigation
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. A sandboxed app may be able to access sensitive user data.
Source : NVD
## 6.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Spotlight
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so yo
Wiz
CVE-2025-43236 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43236 [HIGH] CVE-2025-43236 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43236 :
macOS vulnerability analysis and mitigation
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.
Source : NVD
## 3.3
Score
Published April 2, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Power Management
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related m
Wiz
CVE-2026-28880 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28880 [HIGH] CVE-2026-28880 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28880 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
iCloud
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on wh
Wiz
CVE-2026-20631 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20631 [HIGH] CVE-2026-20631 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20631 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user may be able to elevate privileges.
Source : NVD
## 8.8
Score
Published March 25, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
PackageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA K
Wiz
CVE-2026-28893 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28893 [HIGH] CVE-2026-28893 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28893 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A document may be written to a temporary file when using print preview.
Source : NVD
## 3.3
Score
Published March 25, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CUPS
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Wiz
CVE-2026-28892 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28892 [HIGH] CVE-2026-28892 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28892 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Diagnostics
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related mac
Wiz
CVE-2026-20692 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20692 [HIGH] CVE-2026-20692 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20692 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. "Hide IP Address" and "Block All Remote Content" may not apply to all mail content.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Mail
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's explo
Wiz
CVE-2026-20639 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20639 [HIGH] CVE-2026-20639 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20639 :
macOS vulnerability analysis and mitigation
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3. Processing a maliciously crafted string may lead to heap corruption.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
configd
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related mac
Wiz
CVE-2026-20673 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20673 [HIGH] CVE-2026-20673 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20673 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
Source : NVD
## 5.3
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Mail
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just wha
Wiz
CVE-2026-20618 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20618 [HIGH] CVE-2026-20618 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20618 :
macOS vulnerability analysis and mitigation
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
System Settings
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Tec
Wiz
CVE-2025-43520 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43520 [HIGH] CVE-2025-43520 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43520 :
macOS vulnerability analysis and mitigation
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 50.7
Exploitation Probability (EPSS) 0.3
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk a
Wiz
CVE-2026-28818 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28818 [HIGH] CVE-2026-28818 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28818 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Spotlight
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2026-28822 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28822 [HIGH] CVE-2026-28822 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28822 :
macOS vulnerability analysis and mitigation
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able to cause unexpected app termination.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Audio
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on w
Wiz
CVE-2026-20677 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20677 [HIGH] CVE-2026-20677 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20677 :
macOS vulnerability analysis and mitigation
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.
Source : NVD
## 9
Score
Published February 11, 2026
Severity CRITICAL
CNA Score 9.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Messages
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's explo
Wiz
CVE-2026-20675 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20675 [HIGH] CVE-2026-20675 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20675 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may lead to disclosure of user information.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageIO
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view o
Wiz
CVE-2026-28825 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28825 [HIGH] CVE-2026-28825 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28825 :
macOS vulnerability analysis and mitigation
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
SMB
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related ma
Wiz
CVE-2026-20629 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20629 [HIGH] CVE-2026-20629 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20629 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Foundation
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
T
Wiz
CVE-2026-28835 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28835 [HIGH] CVE-2026-28835 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28835 :
macOS vulnerability analysis and mitigation
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Mounting a maliciously crafted SMB network share may lead to system termination.
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
SMB
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Wiz
CVE-2026-20653 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20653 [HIGH] CVE-2026-20653 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20653 :
macOS vulnerability analysis and mitigation
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Shortcuts
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in you
Wiz
CVE-2024-44219 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2024-44219 [HIGH] CVE-2024-44219 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-44219 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be able to access private information.
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 25.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Sandbox
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE
Wiz
CVE-2026-28877 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28877 [HIGH] CVE-2026-28877 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28877 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Accounts
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's list
Wiz
CVE-2025-43518 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43518 [HIGH] CVE-2025-43518 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43518 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, watchOS 26.2. An app may be able to inappropriately access files through the spellcheck API.
Source : NVD
## 3.3
Score
Published December 12, 2025
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Foundation
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, no
Wiz
CVE-2026-20607 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20607 [HIGH] CVE-2026-20607 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20607 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data.
Source : NVD
## 4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libxpc
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
C
Wiz
CVE-2025-43466 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43466 [HIGH] CVE-2025-43466 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43466 :
macOS vulnerability analysis and mitigation
An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
T
Wiz
CVE-2026-20615 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20615 [HIGH] CVE-2026-20615 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20615 :
macOS vulnerability analysis and mitigation
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS
Wiz
CVE-2026-20617 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20617 [HIGH] CVE-2026-20617 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20617 :
macOS vulnerability analysis and mitigation
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to gain root privileges.
Source : NVD
## 7
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Wiz
CVE-2026-28816 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28816 [HIGH] CVE-2026-28816 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28816 :
macOS vulnerability analysis and mitigation
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to delete files for which it does not have permission.
Source : NVD
## 4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Notes
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS
Wiz
CVE-2026-28882 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28882 [HIGH] CVE-2026-28882 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28882 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
Source : NVD
## 4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libxpc
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnera
Wiz
CVE-2024-44210 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2024-44210 [LOW] CVE-2024-44210 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-44210 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.
Source : NVD
## 3.3
Score
Published January 16, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
StorageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2026-20658 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20658 [HIGH] CVE-2026-20658 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20658 :
macOS vulnerability analysis and mitigation
A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Security
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technolog
Wiz
CVE-2025-46316 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46316 [HIGH] CVE-2025-46316 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46316 :
macOS vulnerability analysis and mitigation
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory.
Source : NVD
## 4.3
Score
Published January 28, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
QuickLook
Spotlight
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus o
Wiz
CVE-2026-28868 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28868 [HIGH] CVE-2026-28868 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28868 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. An app may be able to disclose kernel memory.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what
Wiz
CVE-2026-28867 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28867 [HIGH] CVE-2026-28867 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28867 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to leak sensitive kernel state.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
mDNSResponder
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on
Wiz
CVE-2026-28841 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28841 [HIGH] CVE-2026-28841 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28841 :
macOS vulnerability analysis and mitigation
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
IOGraphics
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Wiz
CVE-2025-43522 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43522 [HIGH] CVE-2025-43522 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43522 :
macOS vulnerability analysis and mitigation
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to access user-sensitive data.
Source : NVD
## 3.3
Score
Published December 12, 2025
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's l
Wiz
CVE-2025-46276 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46276 [HIGH] CVE-2025-46276 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46276 :
macOS vulnerability analysis and mitigation
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Messages
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your clo
Wiz
CVE-2026-28826 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28826 [HIGH] CVE-2026-28826 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28826 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to break out of its sandbox.
Source : NVD
## 4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NSColorPanel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2025-43416 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43416 [HIGH] CVE-2025-43416 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43416 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 9.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
sudo
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Wiz
CVE-2025-46288 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46288 [HIGH] CVE-2025-46288 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46288 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive payment tokens.
Source : NVD
## 5.5
Score
Published December 17, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
App Store
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related m
Wiz
CVE-2026-20700 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20700 [HIGH] CVE-2026-20700 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20700 :
macOS vulnerability analysis and mitigation
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Wiz
CVE-2025-43482 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43482 [HIGH] CVE-2025-43482 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43482 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to cause a denial-of-service.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Audio
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Wiz
CVE-2026-28888 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28888 [HIGH] CVE-2026-28888 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28888 :
macOS vulnerability analysis and mitigation
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain root privileges.
Source : NVD
## 5.1
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CUPS
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Seve
Wiz
CVE-2025-46287 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46287 [HIGH] CVE-2025-46287 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46287 :
macOS vulnerability analysis and mitigation
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An attacker may be able to spoof their FaceTime caller ID.
Source : NVD
## 6.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 9.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Calling Framework
Sources
NVD
## Get a CVE risk assessment
Get a prioritized
Wiz
CVE-2025-43320 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43320 [HIGH] CVE-2025-43320 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43320 :
macOS vulnerability analysis and mitigation
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
Source : NVD
## 7.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's
Wiz
CVE-2025-43410 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43410 [HIGH] CVE-2025-43410 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43410 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.2. An attacker with physical access may be able to view deleted notes.
Source : NVD
## 2.4
Score
Published December 12, 2025
Severity LOW
CNA Score 2.4
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Notes
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnera
Wiz
CVE-2026-20633 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20633 [HIGH] CVE-2026-20633 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20633 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
DesktopServices
Archive Utility
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related m
Wiz
CVE-2025-43381 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43381 [HIGH] CVE-2025-43381 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43381 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to delete protected user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServicesUIAgent
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Sc
Wiz
CVE-2025-43530 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43530 [HIGH] CVE-2025-43530 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43530 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
VoiceOver
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macO
Wiz
CVE-2026-20614 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20614 [HIGH] CVE-2026-20614 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20614 :
macOS vulnerability analysis and mitigation
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Remote Management
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilitie
Wiz
CVE-2026-20684 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20684 [HIGH] CVE-2026-20684 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20684 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.
Source : NVD
## 3.3
Score
Published March 25, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleScript
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
Wiz
CVE-2025-46277 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46277 [HIGH] CVE-2025-46277 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46277 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, watchOS 26.2. An app may be able to access a user’s Safari history.
Source : NVD
## 3.3
Score
Published December 17, 2025
Severity LOW
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Screen Time
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2025-46297 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46297 [HIGH] CVE-2025-46297 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46297 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an App Sandbox container.
Source : NVD
## 5.5
Score
Published January 9, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppSandbox
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
S
Wiz
CVE-2025-43497 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43497 [HIGH] CVE-2025-43497 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43497 :
macOS vulnerability analysis and mitigation
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of its sandbox.
Source : NVD
## 5.2
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
BackBoardServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
T
Wiz
CVE-2026-20612 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20612 [HIGH] CVE-2026-20612 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20612 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Spotlight
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE I
Wiz
CVE-2026-20605 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20605 [HIGH] CVE-2026-20605 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20605 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to crash a system process.
Source : NVD
## 4.6
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 4.6
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Voice Control
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Relat
Wiz
CVE-2026-20609 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20609 [HIGH] CVE-2026-20609 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20609 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
Source : NVD
## 4.4
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreMedia
Sources
NVD
## Get a CVE risk asses
Wiz
CVE-2025-43351 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43351 [HIGH] CVE-2025-43351 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43351 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
StorageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologi
Wiz
CVE-2026-28891 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28891 [HIGH] CVE-2026-28891 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28891 :
macOS vulnerability analysis and mitigation
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
Source : NVD
## 8.1
Score
Published March 25, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NetAuth
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
S
Wiz
CVE-2026-20688 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20688 [HIGH] CVE-2026-20688 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20688 :
macOS vulnerability analysis and mitigation
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.
Source : NVD
## 9.3
Score
Published March 25, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Printing
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's list
Wiz
CVE-2025-46285 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46285 [HIGH] CVE-2025-46285 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46285 :
macOS vulnerability analysis and mitigation
An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you ca
Wiz
CVE-2025-46281 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-46281 [HIGH] CVE-2025-46281 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-46281 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.2. An app may be able to break out of its sandbox.
Source : NVD
## 8.8
Score
Published December 17, 2025
Severity HIGH
CNA Score 8.4
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
File Bookmark
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component n
Wiz
CVE-2026-20657 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20657 [HIGH] CVE-2026-20657 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20657 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5. Parsing a maliciously crafted file may lead to an unexpected app termination.
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Vision
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
##
Wiz
CVE-2024-44250 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2024-44250 [HIGH] CVE-2024-44250 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-44250 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Source : NVD
## 8.2
Score
Published April 2, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
XPC
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabiliti
Wiz
CVE-2026-28866 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28866 [HIGH] CVE-2026-28866 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28866 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Clipboard
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not
Wiz
CVE-2026-20649 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20649 [HIGH] CVE-2026-20649 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20649 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.
Source : NVD
## 7.5
Score
Published February 11, 2026
Severity HIGH
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Game Center
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vul
Wiz
CVE-2026-20624 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20624 [HIGH] CVE-2026-20624 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20624 :
macOS vulnerability analysis and mitigation
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vu
Wiz
CVE-2025-43210 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-43210 [MEDIUM] CVE-2025-43210 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43210 :
macOS vulnerability analysis and mitigation
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
Source : NVD
## 6.3
Score
Published April 2, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreMedia
Sources
NVD
## Get a CVE risk asse
Wiz
CVE-2026-28827 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28827 [HIGH] CVE-2026-28827 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28827 :
macOS vulnerability analysis and mitigation
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
Source : NVD
## 9.3
Score
Published March 25, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NetFSFramework
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's liste
Wiz
CVE-2026-28824 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28824 [HIGH] CVE-2026-28824 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28824 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related
Wiz
CVE-2026-28852 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28852 [HIGH] CVE-2026-28852 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28852 :
macOS vulnerability analysis and mitigation
A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause a denial-of-service.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
UIFoundation
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on wh
Wiz
CVE-2026-20601 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20601 [HIGH] CVE-2026-20601 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20601 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.
Source : NVD
## 3.3
Score
Published February 11, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Foundation
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Scor
Wiz
CVE-2025-43527 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43527 [HIGH] CVE-2025-43527 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43527 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
StorageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Sco
Wiz
CVE-2026-20698 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20698 [HIGH] CVE-2026-20698 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20698 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or corrupt kernel memory.
Source : NVD
## 7.8
Score
Published March 25, 2026
Severity HIGH
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what'
Wiz
CVE-2025-43428 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43428 [HIGH] CVE-2025-43428 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43428 :
macOS vulnerability analysis and mitigation
A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Photos in the Hidden Photos Album may be viewed without authentication.
Source : NVD
## 9.8
Score
Published December 17, 2025
Severity CRITICAL
CNA Score 9.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Photos
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Rela
Wiz
CVE-2026-20626 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20626 [HIGH] CVE-2026-20626 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20626 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabili
Wiz
CVE-2025-43506 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43506 [HIGH] CVE-2025-43506 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43506 :
macOS vulnerability analysis and mitigation
A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay may not activate when more than one user is logged in at the same time.
Source : NVD
## 7.5
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Networking
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2024-40849 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2024-40849 [HIGH] CVE-2024-40849 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-40849 :
macOS vulnerability analysis and mitigation
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
LaunchServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Co
Wiz
CVE-2026-20641 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20641 [HIGH] CVE-2026-20641 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20641 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to identify what other apps a user has installed.
Source : NVD
## 7.1
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
StoreKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your c
Wiz
CVE-2025-43238 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43238 [HIGH] CVE-2025-43238 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43238 :
macOS vulnerability analysis and mitigation
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.
Source : NVD
## 6.2
Score
Published April 2, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Xsan
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerab
Wiz
CVE-2026-28821 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28821 [HIGH] CVE-2026-28821 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28821 :
macOS vulnerability analysis and mitigation
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain elevated privileges.
Source : NVD
## 8.4
Score
Published March 25, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what'
Wiz
CVE-2025-43402 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43402 [HIGH] CVE-2025-43402 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43402 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.1. An app may be able to cause unexpected system termination or corrupt process memory.
Source : NVD
## 7.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
WindowServer
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
##
Wiz
CVE-2025-43494 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43494 [HIGH] CVE-2025-43494 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43494 :
macOS vulnerability analysis and mitigation
A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An attacker may be able to cause a persistent denial-of-service.
Source : NVD
## 7.5
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 30.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Mail
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—s
Wiz
CVE-2026-20625 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20625 [HIGH] CVE-2026-20625 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20625 :
macOS vulnerability analysis and mitigation
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploi
Wiz
CVE-2026-28864 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28864 [HIGH] CVE-2026-28864 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28864 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may gain access to user's Keychain items.
Source : NVD
## 3.3
Score
Published March 25, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Security
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can fo
Wiz
CVE-2025-43219 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43219 [HIGH] CVE-2025-43219 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43219 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.
Source : NVD
## 8.8
Score
Published April 2, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Model I/O
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technol
Wiz
CVE-2025-43417 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43417 [HIGH] CVE-2025-43417 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43417 :
macOS vulnerability analysis and mitigation
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access user-sensitive data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
File Bookmark
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Wiz
CVE-2026-20606 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20606 [HIGH] CVE-2026-20606 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20606 :
macOS vulnerability analysis and mitigation
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to bypass certain Privacy preferences.
Source : NVD
## 7.1
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
UIKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not
Wiz
CVE-2025-43538 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43538 [HIGH] CVE-2025-43538 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43538 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Screen Time
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploit
Wiz
CVE-2026-20622 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20622 [HIGH] CVE-2026-20622 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20622 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to capture a user's screen.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Shortcuts
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Seve
Wiz
CVE-2025-43463 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43463 [HIGH] CVE-2025-43463 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43463 :
macOS vulnerability analysis and mitigation
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
StorageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed
Wiz
CVE-2026-20628 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20628 [HIGH] CVE-2026-20628 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20628 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
Source : NVD
## 7.1
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Sandbox
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so yo
Wiz
CVE-2026-20637 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20637 [HIGH] CVE-2026-20637 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20637 :
macOS vulnerability analysis and mitigation
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleKeyStore
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CV
Wiz
CVE-2026-28862 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28862 [HIGH] CVE-2026-28862 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28862 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Phone
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macO
Wiz
CVE-2026-28831 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28831 [HIGH] CVE-2026-28831 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28831 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Printing
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabili
Wiz
CVE-2026-20690 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20690 [HIGH] CVE-2026-20690 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20690 :
macOS vulnerability analysis and mitigation
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing an audio stream in a maliciously crafted media file may terminate the process.
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreMedia
Sources
NVD
## Get a CVE risk assessment
Wiz
CVE-2026-20623 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20623 [HIGH] CVE-2026-20623 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20623 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Foundation
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technol
Wiz
CVE-2026-20687 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20687 [HIGH] CVE-2026-20687 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20687 :
macOS vulnerability analysis and mitigation
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.
Source : NVD
## 7.1
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so y
Wiz
CVE-2026-28842 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28842 [HIGH] CVE-2026-28842 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28842 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
IOGraphics
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Wiz
CVE-2025-43523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43523 [HIGH] CVE-2025-43523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43523 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2025-43509 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43509 [HIGH] CVE-2025-43509 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43509 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Networking
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2026-28894 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28894 [HIGH] CVE-2026-28894 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28894 :
macOS vulnerability analysis and mitigation
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 40.4
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
Calling Framework
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not jus
Wiz
CVE-2026-20620 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20620 [HIGH] CVE-2026-20620 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20620 :
macOS vulnerability analysis and mitigation
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An attacker may be able to cause unexpected system termination or read kernel memory.
Source : NVD
## 7.7
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
GPU Drivers
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just
Wiz
CVE-2024-44286 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2024-44286 [HIGH] CVE-2024-44286 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-44286 :
macOS vulnerability analysis and mitigation
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
LaunchServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilitie
Wiz
CVE-2026-20699 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20699 [HIGH] CVE-2026-20699 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20699 :
macOS vulnerability analysis and mitigation
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to access user-sensitive data.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Spotlight
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you
Wiz
CVE-2026-28838 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28838 [HIGH] CVE-2026-28838 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28838 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulne
Wiz
CVE-2026-28845 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28845 [HIGH] CVE-2026-28845 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28845 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
LaunchServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Tech
Wiz
CVE-2026-28823 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28823 [HIGH] CVE-2026-28823 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28823 :
macOS vulnerability analysis and mitigation
A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.4. An app with root privileges may be able to delete protected system files.
Source : NVD
## 4.9
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Admin Framework
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Se
Wiz
CVE-2025-43473 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43473 [HIGH] CVE-2025-43473 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43473 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Shortcuts
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Compon
Wiz
CVE-2025-43461 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43461 [HIGH] CVE-2025-43461 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43461 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
configd
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2026-28820 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28820 [HIGH] CVE-2026-28820 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28820 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
StorageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
Wiz
CVE-2026-20619 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20619 [HIGH] CVE-2026-20619 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20619 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
System Settings
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Seve
Wiz
CVE-2026-20669 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20669 [HIGH] CVE-2026-20669 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20669 :
macOS vulnerability analysis and mitigation
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Admin Framework
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2026-20634 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20634 [HIGH] CVE-2026-20634 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20634 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may result in disclosure of process memory.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ImageIO
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view
Wiz
CVE-2026-28844 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28844 [HIGH] CVE-2026-28844 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28844 :
macOS vulnerability analysis and mitigation
A file access issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.4. An attacker may gain access to protected parts of the file system.
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
SystemMigration
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Sever
Wiz
CVE-2025-43513 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43513 [HIGH] CVE-2025-43513 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43513 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to read sensitive location information.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
MDM Configuration Tools
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
##
Wiz
CVE-2026-20667 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20667 [HIGH] CVE-2026-20667 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20667 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
Source : NVD
## 8.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libxpc
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related
Wiz
CVE-2026-28879 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28879 [HIGH] CVE-2026-28879 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28879 :
macOS vulnerability analysis and mitigation
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Audio
Sources
NVD
## Get a CVE risk assessment
Get a prio
Wiz
CVE-2026-28828 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28828 [HIGH] CVE-2026-28828 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28828 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12
Exploitation Probability (EPSS) N/A
Affected packages and libraries
TCC
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2026-20694 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20694 [HIGH] CVE-2026-20694 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20694 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to access user-sensitive data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
MigrationKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can
Wiz
CVE-2026-20646 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20646 [HIGH] CVE-2026-20646 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20646 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.
Source : NVD
## 3.3
Score
Published February 11, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Weather
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Te
Wiz
CVE-2026-28829 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28829 [HIGH] CVE-2026-28829 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28829 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
WebDAV
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related m
Wiz
CVE-2026-20611 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20611 [HIGH] CVE-2026-20611 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20611 :
macOS vulnerability analysis and mitigation
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
CoreAudio
Sources
NVD
## Get
Wiz
CVE-2026-20616 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20616 [HIGH] CVE-2026-20616 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20616 :
macOS vulnerability analysis and mitigation
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.
Source : NVD
## 8.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Model I/O
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's expl
Wiz
CVE-2026-28833 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28833 [HIGH] CVE-2026-28833 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28833 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. An app may be able to enumerate a user's installed apps.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
iCloud
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabiliti
Wiz
CVE-2026-20668 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20668 [HIGH] CVE-2026-20668 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20668 :
macOS vulnerability analysis and mitigation
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Focus
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploita
Wiz
CVE-2026-20603 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20603 [HIGH] CVE-2026-20603 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20603 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An app with root privileges may be able to access private information.
Source : NVD
## 4.4
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Notification Center
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabiliti
Wiz
CVE-2026-20671 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20671 [HIGH] CVE-2026-20671 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20671 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to intercept network traffic.
Source : NVD
## 3.1
Score
Published February 11, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libnetcore
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritiz
Wiz
CVE-2026-28834 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28834 [HIGH] CVE-2026-28834 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28834 :
macOS vulnerability analysis and mitigation
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to cause unexpected system termination.
Source : NVD
## 5.1
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
GPU Drivers
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabi
Wiz
CVE-2026-28870 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28870 [HIGH] CVE-2026-28870 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28870 :
macOS vulnerability analysis and mitigation
An information leakage was addressed with additional validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
GeoServices
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Rel
Wiz
CVE-2025-43519 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43519 [HIGH] CVE-2025-43519 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43519 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
SoftwareUpdate
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Wiz
CVE-2025-43464 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43464 [HIGH] CVE-2025-43464 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43464 :
macOS vulnerability analysis and mitigation
A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.1. Visiting a website may lead to an app denial-of-service.
Source : NVD
## 6.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 6.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
dyld
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Wiz
CVE-2026-28817 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28817 [HIGH] CVE-2026-28817 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28817 :
macOS vulnerability analysis and mitigation
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.
Source : NVD
## 8.1
Score
Published March 25, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Printing
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulne
Wiz
CVE-2025-43516 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43516 [HIGH] CVE-2025-43516 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43516 :
macOS vulnerability analysis and mitigation
A session management issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. A user with Voice Control enabled may be able to transcribe another user's activity.
Source : NVD
## 3.3
Score
Published December 12, 2025
Severity LOW
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Voice Control
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's list
Wiz
CVE-2025-43467 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43467 [HIGH] CVE-2025-43467 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43467 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to gain root privileges.
Source : NVD
## 7.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Installer
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA K
Wiz
CVE-2026-28837 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28837 [HIGH] CVE-2026-28837 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28837 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
System Settings
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component
Wiz
CVE-2024-40858 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2024-40858 [HIGH] CVE-2024-40858 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2024-40858 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user consent.
Source : NVD
## 7.1
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
Photos
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technol
Wiz
CVE-2025-43388 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43388 [HIGH] CVE-2025-43388 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43388 :
macOS vulnerability analysis and mitigation
An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
T
Wiz
CVE-2026-28876 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28876 [HIGH] CVE-2026-28876 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28876 :
macOS vulnerability analysis and mitigation
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to access sensitive user data.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
DeviceLink
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your c
Wiz
CVE-2026-20693 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20693 [HIGH] CVE-2026-20693 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20693 :
macOS vulnerability analysis and mitigation
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An attacker with root privileges may be able to delete protected system files.
Source : NVD
## 4.9
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 4.9
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
PackageKit
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Re
Wiz
CVE-2026-28881 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28881 [HIGH] CVE-2026-28881 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28881 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
iCloud
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component nam
Wiz
CVE-2025-43510 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43510 [HIGH] CVE-2025-43510 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43510 :
macOS vulnerability analysis and mitigation
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
Source : NVD
## 7.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 66.4
Exploitation Probability (EPSS) 0.5
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessmen
Wiz
CVE-2025-43264 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43264 [HIGH] CVE-2025-43264 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43264 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.
Source : NVD
## 8.8
Score
Published April 2, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Model I/O
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technol
Wiz
CVE-2025-43512 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43512 [HIGH] CVE-2025-43512 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43512 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to elevate privileges.
Source : NVD
## 7.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabi
Wiz
CVE-2025-43539 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43539 [HIGH] CVE-2025-43539 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43539 :
macOS vulnerability analysis and mitigation
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing a file may lead to memory corruption.
Source : NVD
## 8.8
Score
Published December 12, 2025
Severity HIGH
CNA Score 8.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleJPEG
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can f
Wiz
CVE-2026-20695 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20695 [HIGH] CVE-2026-20695 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20695 :
macOS vulnerability analysis and mitigation
An information disclosure issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to determine kernel memory layout.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Kernel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS
Wiz
CVE-2026-20666 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20666 [HIGH] CVE-2026-20666 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20666 :
macOS vulnerability analysis and mitigation
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NSOpenPanel
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Techno
Wiz
CVE-2025-43521 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43521 [HIGH] CVE-2025-43521 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43521 :
macOS vulnerability analysis and mitigation
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
AppleMobileFileIntegrity
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what'
Wiz
CVE-2026-20651 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20651 [HIGH] CVE-2026-20651 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20651 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Messages
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnera
Wiz
CVE-2026-20697 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20697 [HIGH] CVE-2026-20697 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20697 :
macOS vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
Source : NVD
## 5.3
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Spotlight
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
Wiz
CVE-2025-43406 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43406 [HIGH] CVE-2025-43406 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43406 :
macOS vulnerability analysis and mitigation
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Sandbox
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Compone
Wiz
CVE-2025-43465 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43465 [HIGH] CVE-2025-43465 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43465 :
macOS vulnerability analysis and mitigation
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published December 12, 2025
Severity MEDIUM
CNA Score 3.3
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ATS
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Se
Wiz
CVE-2025-43202 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43202 [HIGH] CVE-2025-43202 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43202 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.
Source : NVD
## 8.8
Score
Published April 2, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libnetcore
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Scor
Wiz
CVE-2025-43257 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2025-43257 [HIGH] CVE-2025-43257 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43257 :
macOS vulnerability analysis and mitigation
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.
Source : NVD
## 8.7
Score
Published April 2, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Archive Utility
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Co
Wiz
CVE-2026-28865 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-28865 [HIGH] CVE-2026-28865 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28865 :
macOS vulnerability analysis and mitigation
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker in a privileged network position may be able to intercept network traffic.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 26
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
802.1X
Sources
NVD
## Get a CVE risk assessment
Get a prio
2026-04-02
Published