Apple macOS vulnerabilities
3,139 known vulnerabilities affecting apple/mac_os_x.
Total CVEs
3,139
CISA KEV
26
actively exploited
Public exploits
279
Exploited in wild
40
Severity breakdown
CRITICAL302HIGH1409MEDIUM1237LOW191
Vulnerabilities
Page 126 of 157
CVE-2020-9811P4MEDIUMCVSS 5.5fixed in 10.15.52020-06-09
CVE-2020-9811 [MEDIUM] CVE-2020-9811: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A local user may be able to read kernel memory.
nvd
CVE-2020-3914P4MEDIUMCVSS 5.5fixed in 10.15.42020-04-01
CVE-2020-3914 [MEDIUM] CWE-401 CVE-2020-3914: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to read restricted memory.
nvd
CVE-2018-4433P4MEDIUMCVSS 5.5fixed in 10.14.4fixed in 10.142020-10-27
CVE-2018-4433 [MEDIUM] CVE-2018-4433: A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojav
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, watchOS 5, iOS 12, tvOS 12, macOS Mojave 10.14. A malicious application may be able to modify protected parts of the file system.
nvd
CVE-2021-30673P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30673 [MEDIUM] CVE-2021-30673: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Su
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A malicious application may be able to access a user's call history.
nvd
CVE-2021-1781P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.6≥ 10.15, < 10.15.7+2 more2021-04-02
CVE-2021-1781 [MEDIUM] CVE-2021-1781: A privacy issue existed in the handling of Contact cards. This was addressed with improved state man
A privacy issue existed in the handling of Contact cards. This was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A malicious application may be able to leak sensitive user information.
nvd
CVE-2018-4173P4MEDIUMCVSS 5.5fixed in 10.13.42018-04-13
CVE-2018-4173 [MEDIUM] CWE-269 CVE-2018-4173: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.
nvd
CVE-2018-4468P4MEDIUMCVSS 5.5≥ 10.14, < 10.14.12020-10-27
CVE-2018-4468 [MEDIUM] CVE-2018-4468: This issue was addressed by removing additional entitlements. This issue is fixed in macOS Mojave 10
This issue was addressed by removing additional entitlements. This issue is fixed in macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra. A malicious application may be able to access restricted files.
nvd
CVE-2011-0207P4MEDIUMCVSS 5.0v10.6.0v10.6.1+6 more2011-06-24
CVE-2011-0207 [MEDIUM] CWE-310 CVE-2011-0207: The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail ap
The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network.
nvd
CVE-2021-30731P4MEDIUMCVSS 5.5≥ 10.15, ≤ 10.15.6v10.15.72021-09-08
CVE-2021-30731 [MEDIUM] CVE-2021-30731: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security U
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Catalina. An unprivileged application may be able to capture USB devices.
nvd
CVE-2022-26727P4MEDIUMCVSS 5.5≥ 10.15, < 10.15.7v10.15.72022-05-26
CVE-2022-26727 [MEDIUM] CVE-2022-26727: This issue was addressed with improved entitlements. This issue is fixed in Security Update 2022-004
This issue was addressed with improved entitlements. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. A malicious application may be able to modify protected parts of the file system.
nvd
CVE-2008-0041P4MEDIUMCVSS 5.0v10.5v10.5.12008-02-12
CVE-2008-0041 [MEDIUM] CWE-200 CVE-2008-0041: Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is un
Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running Parental Controls.
nvd
CVE-2022-32834P4MEDIUMCVSS 5.5v10.15.72022-08-24
CVE-2022-32834 [MEDIUM] CWE-284 CVE-2022-32834: An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Montere
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.
nvd
CVE-2018-4225P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4225 [MEDIUM] CWE-20 CVE-2018-4225: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended restrictions on Keychain state mo
nvd
CVE-2018-4226P4MEDIUMCVSS 5.5fixed in 10.13.52018-06-08
CVE-2018-4226 [MEDIUM] CWE-200 CVE-2018-4226: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. watchOS before 4.3.1 is affected. The issue involves the "Security" component. It allows local users to bypass intended restrictions on the reading of s
nvd
CVE-2006-4407P4MEDIUMCVSS 5.0v10.3v10.3.1+7 more2006-11-30
CVE-2006-4407 [MEDIUM] CVE-2006-4407: The Security Framework in Apple Mac OS X 10.3.x up to 10.3.9 does not properly prioritize encryption
The Security Framework in Apple Mac OS X 10.3.x up to 10.3.9 does not properly prioritize encryption ciphers when negotiating the strongest shared cipher, which causes Secure Transport to user a weaker cipher that makes it easier for remote attackers to decrypt traffic.
nvd
CVE-2021-30669P4MEDIUMCVSS 5.5≥ 10.14, ≤ 10.14.5≥ 10.15, ≤ 10.15.6+2 more2021-09-08
CVE-2021-30669 [MEDIUM] CWE-494 CVE-2021-30669: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may bypass Gatekeeper checks.
nvd
CVE-2022-32805P4MEDIUMCVSS 5.5v10.15.72022-09-23
CVE-2022-32805 [MEDIUM] CWE-200 CVE-2022-32805: The issue was addressed with improved handling of caches. This issue is fixed in Security Update 202
The issue was addressed with improved handling of caches. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to access sensitive user information.
nvd
CVE-2020-9969P4MEDIUMCVSS 5.5fixed in 11.0.12020-12-08
CVE-2020-9969 [MEDIUM] CVE-2020-9969: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. A local user may be able to view senstive user information.
nvd
CVE-2019-8691P4MEDIUMCVSS 5.5fixed in 10.14.62019-12-18
CVE-2019-8691 [MEDIUM] CWE-125 CVE-2019-8691: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An application may be able to read restricted memory.
nvd
CVE-2020-3881P4MEDIUMCVSS 5.5fixed in 10.15.42020-04-01
CVE-2020-3881 [MEDIUM] CVE-2020-3881: A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10
A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to view sensitive user information.
nvd