Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 105 of 172
CVE-2024-40827P4MEDIUMCVSS 5.5fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-40827 [MEDIUM] CVE-2024-40827: The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS So
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to overwrite arbitrary files.
nvd
CVE-2024-44190P4MEDIUMCVSS 5.5fixed in 13.7≥ 14.0, < 14.7+2 more2024-09-17
CVE-2024-44190 [MEDIUM] CWE-22 CVE-2024-44190: A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 1
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to read arbitrary files.
nvd
CVE-2024-54520P4MEDIUMCVSS 5.5fixed in 13.7.2≥ 14.0, < 14.7.2+3 more2025-01-27
CVE-2024-54520 [MEDIUM] CWE-22 CVE-2024-54520: A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 1
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.
nvd
CVE-2025-43444P4MEDIUMCVSS 5.3fixed in 26.12025-11-04
CVE-2025-43444 [MEDIUM] CWE-276 CVE-2025-43444: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 an
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.
nvd
CVE-2026-20692P4MEDIUMCVSS 5.3≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-20692 [MEDIUM] CVE-2026-20692: A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. "Hide IP Address" and "Block All Remote Content" may not apply to all mail content.
nvd
CVE-2025-43308P4MEDIUMCVSS 5.3≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43308 [MEDIUM] CWE-284 CVE-2025-43308: This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access sensitive user data.
nvd
CVE-2026-20673P4MEDIUMCVSS 5.3fixed in 14.8.4≥ 15.0, < 15.7.4+3 more2026-02-11
CVE-2026-20673 [MEDIUM] CVE-2026-20673: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
nvd
CVE-2026-28820P4MEDIUMCVSS 5.3≥ 26.0, < 26.4fixed in 26.42026-03-25
CVE-2026-28820 [MEDIUM] CWE-200 CVE-2026-28820: This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may b
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.
nvd
CVE-2026-28823P4MEDIUMCVSS 4.9≥ 26.0, < 26.4fixed in 26.42026-03-25
CVE-2026-28823 [MEDIUM] CWE-284 CVE-2026-28823: A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.
A path handling issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.4. An app with root privileges may be able to delete protected system files.
nvd
CVE-2024-23248P4HIGHCVSS 7.1≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23248 [HIGH] CWE-404 CVE-2024-23248: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Pro
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2023-27968P4HIGHCVSS 7.1≥ 13.0, < 13.3≥ unspecified, < 13.32023-05-08
CVE-2023-27968 [HIGH] CWE-120 CVE-2023-27968: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ve
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2024-23249P4HIGHCVSS 7.1≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23249 [HIGH] CWE-404 CVE-2024-23249: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Pro
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2023-28179P4HIGHCVSS 7.1≥ 13.0, < 13.3≥ unspecified, < 13.32023-08-14
CVE-2023-28179 [HIGH] CVE-2023-28179: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Pr
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted AppleScript binary may result in unexpected app termination or disclosure of process memory.
nvd
CVE-2023-38610P4HIGHCVSS 7.1fixed in 14.0≥ unspecified, < 142024-01-10
CVE-2023-38610 [HIGH] CWE-787 CVE-2023-38610: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macO
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2023-42876P4HIGHCVSS 7.1fixed in 14.0≥ unspecified, < 142024-01-10
CVE-2023-42876 [HIGH] CVE-2023-42876: The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. Process
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2020-27935P4MEDIUMCVSS 6.3≥ unspecified, < 11.02021-04-02
CVE-2020-27935 [MEDIUM] CVE-2020-27935: Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2,
Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2018-4478P4MEDIUMCVSS 6.8≥ unspecified, < 10.132021-12-23
CVE-2018-4478 [MEDIUM] CWE-269 CVE-2018-4478: A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13
A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Update 2018-003 El Capitan. An attacker with physical access to a device may be able to elevate privileges.
nvd
CVE-2025-43424P4MEDIUMCVSS 6.5fixed in 26.12025-11-04
CVE-2025-43424 [MEDIUM] CWE-119 CVE-2025-43424: The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.1 and iPadOS 26.1
The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. A malicious HID device may cause an unexpected process crash.
nvd
CVE-2021-30813P4MEDIUMCVSS 6.5fixed in 12.0.1≥ unspecified, < 12.02021-10-28
CVE-2021-30813 [MEDIUM] CVE-2021-30813: This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. A perso
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. A person with access to a host Mac may be able to bypass the Login Window in Remote Desktop for a locked instance of macOS.
nvd
CVE-2022-26766P4MEDIUMCVSS 5.5≥ 11.0, < 11.6.6≥ 12.0, < 12.42022-05-26
CVE-2022-26766 [MEDIUM] CWE-295 CVE-2022-26766: A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iO
A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.
nvd