Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 106 of 172
CVE-2025-43240P4MEDIUMCVSS 6.2fixed in 15.62025-07-30
CVE-2025-43240 [MEDIUM] CWE-703 CVE-2025-43240: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia
A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
nvd
CVE-2022-32786P4MEDIUMCVSS 5.5fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32786 [MEDIUM] CWE-20 CVE-2022-32786: An issue in the handling of environment variables was addressed with improved validation. This issue
An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.
nvd
CVE-2020-10012P4MEDIUMCVSS 6.1fixed in 11.0.1≥ unspecified, < 11.02020-12-08
CVE-2020-10012 [MEDIUM] CWE-79 CVE-2020-10012: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Su
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted document may lead to a cross site scripting attack.
nvd
CVE-2022-32800P4MEDIUMCVSS 5.5fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32800 [MEDIUM] CWE-284 CVE-2022-32800: This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catal
This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.
nvd
CVE-2022-29046P4MEDIUMCVSS 5.4≥ 12.0, < 12.52022-04-12
CVE-2022-29046 [MEDIUM] CWE-79 CVE-2022-29046: Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subver
Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more) parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
nvd
CVE-2024-23223P4MEDIUMCVSS 6.2≥ 14.0, < 14.3fixed in 14.32024-01-23
CVE-2024-23223 [MEDIUM] CWE-732 CVE-2024-23223: A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and i
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to access sensitive user data.
nvd
CVE-2021-1883P4MEDIUMCVSS 5.5≥ 11.0, < 11.3≥ unspecified, < 11.3+1 more2021-09-08
CVE-2021-1883 [MEDIUM] CWE-787 CVE-2021-1883: This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojav
This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted server messages may lead to heap corruption.
nvd
CVE-2026-28866P4MEDIUMCVSS 6.2≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-28866 [MEDIUM] CWE-59 CVE-2026-28866: This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.
nvd
CVE-2025-43279P4MEDIUMCVSS 6.2fixed in 26.0fixed in 262025-09-15
CVE-2025-43279 [MEDIUM] CWE-359 CVE-2025-43279: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.
nvd
CVE-2025-43318P4MEDIUMCVSS 6.2fixed in 26.0fixed in 262025-09-15
CVE-2025-43318 [MEDIUM] CWE-862 CVE-2025-43318: This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26.
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26. An app with root privileges may be able to access private information.
nvd
CVE-2026-43653P4MEDIUMCVSS 6.2≥ 14.0, < 14.8.7≥ 26.0, < 26.5+3 more2026-05-11
CVE-2026-43653 [MEDIUM] CWE-400 CVE-2026-43653: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2022-22583P4MEDIUMCVSS 5.5fixed in 11.6.3≥ 12.0.0, < 12.3+4 more2022-03-18
CVE-2022-22583 [MEDIUM] CVE-2022-22583: A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2
A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access restricted files.
nvd
CVE-2021-30912P4MEDIUMCVSS 5.5≥ 11.0, < 11.6.1v12.0+3 more2021-08-24
CVE-2021-30912 [MEDIUM] CWE-281 CVE-2021-30912: The issue was addressed with improved permissions logic. This issue is fixed in macOS Monterey 12.0.
The issue was addressed with improved permissions logic. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may gain access to a user's Keychain items.
nvd
CVE-2019-8768P4MEDIUMCVSS 5.3≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8768 [MEDIUM] CWE-459 CVE-2019-8768: "Clear History and Website Data" did not clear the history. The issue was addressed with improved da
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.
nvd
CVE-2021-1760P4MEDIUMCVSS 5.5≥ 11.0, < 11.2≥ unspecified, < 11.2+2 more2021-04-02
CVE-2021-1760 [MEDIUM] CWE-787 CVE-2021-1760: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application could execute arbitrary code leading to compromise of user information.
nvd
CVE-2019-8530P4MEDIUMCVSS 5.5≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8530 [MEDIUM] CVE-2019-8530: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2024-54507P4MEDIUMCVSS 5.5fixed in 15.22025-01-27
CVE-2024-54507 [MEDIUM] CWE-843 CVE-2024-54507: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel memory.
nvd
CVE-2025-24270P4MEDIUMCVSS 5.7fixed in 13.7.5≥ 14.0, < 14.7.5+3 more2025-04-29
CVE-2025-24270 [MEDIUM] CWE-200 CVE-2025-24270: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to leak sensitive user information.
nvd
CVE-2019-8521P4MEDIUMCVSS 5.5≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8521 [MEDIUM] CVE-2019-8521: This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4
This issue was addressed with improved checks. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2020-9787P4MEDIUMCVSS 5.3≥ unspecified, < macOS Catalina 10.15.42020-10-22
CVE-2020-9787 [MEDIUM] CVE-2020-9787: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. Some websites may not have appeared in Safari Preferences.
nvd