cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 108 of 172
CVE-2025-24096P4MEDIUMCVSS 5.5fixed in 15.32025-01-27
CVE-2025-24096 [MEDIUM] CWE-862 CVE-2025-24096: This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15. This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrary files.
nvd
CVE-2022-32943P4MEDIUMCVSS 5.3v13.0≥ unspecified, < 13.1+1 more2022-12-15
CVE-2022-32943 [MEDIUM] CWE-125 CVE-2022-32943: The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
nvd
CVE-2025-43466P4MEDIUMCVSS 5.5fixed in 26.12025-12-12
CVE-2025-43466 [MEDIUM] CWE-95 CVE-2025-43466: An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2026-20625P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.4≥ 15.0, < 15.7.4+4 more2026-02-11
CVE-2026-20625 [MEDIUM] CWE-22 CVE-2026-20625: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
nvd
CVE-2025-43463P4MEDIUMCVSS 5.5fixed in 14.8.3≥ 15.0, < 15.7.3+3 more2025-12-12
CVE-2025-43463 [MEDIUM] CWE-22 CVE-2025-43463: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2025-43382P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.2≥ 15.0, < 15.7.2+3 more2025-11-04
CVE-2025-43382 [MEDIUM] CWE-22 CVE-2025-43382: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2025-43388P4MEDIUMCVSS 5.5fixed in 26.12025-12-12
CVE-2025-43388 [MEDIUM] CWE-95 CVE-2025-43388: An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An injection issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2024-54466P4MEDIUMCVSS 5.3≥ 13.0, < 13.7.2≥ 14.0, < 14.7.2+4 more2024-12-12
CVE-2024-54466 [MEDIUM] CWE-862 CVE-2024-54466: An authorization issue was addressed with improved state management. This issue is fixed in macOS Se An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An encrypted volume may be accessed by a different user without prompting for the password.
nvd
CVE-2025-43465P4MEDIUMCVSS 5.5fixed in 26.12025-12-12
CVE-2025-43465 [MEDIUM] CWE-22 CVE-2025-43465: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2025-43389P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.2≥ 15.0, < 15.7.2+3 more2025-11-04
CVE-2025-43389 [MEDIUM] CWE-359 CVE-2025-43389: A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data.
nvd
CVE-2025-43469P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.2≥ 15.0, < 15.7.2+3 more2025-11-04
CVE-2025-43469 [MEDIUM] CWE-359 CVE-2025-43469: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2026-28892P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-28892 [MEDIUM] CVE-2026-28892: A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequ A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.
nvd
CVE-2025-31248P4MEDIUMCVSS 5.5fixed in 13.7.3≥ 14.0, < 14.7.3+3 more2025-11-21
CVE-2025-31248 [MEDIUM] CWE-22 CVE-2025-31248: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access sensitive user data.
nvd
CVE-2022-32928P4MEDIUMCVSS 5.3fixed in 13.0≥ unspecified, < 13+1 more2022-11-01
CVE-2022-32928 [MEDIUM] CWE-287 CVE-2022-32928: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.
nvd
CVE-2026-64722P4MEDIUMCVSS 5.5≥ 15.0, < 15.7.8≥ 26.0, < 26.6+2 more2026-07-27
CVE-2026-64722 [MEDIUM] CWE-120 CVE-2026-64722: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a 3D model may result in disclosure of process memory.
nvd
CVE-2025-24268P4MEDIUMCVSS 5.5fixed in 15.42026-06-11
CVE-2025-24268 [MEDIUM] CWE-22 CVE-2025-24268: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
nvd
CVE-2025-43451P4MEDIUMCVSS 5.5fixed in 26.0fixed in 262026-05-26
CVE-2025-43451 [MEDIUM] CWE-284 CVE-2025-43451: A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Taho A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
nvd
CVE-2026-43796P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-43796 [MEDIUM] CWE-200 CVE-2026-43796: This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 2 This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-20669P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20669 [MEDIUM] CWE-22 CVE-2026-20669: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.
nvd
CVE-2025-30459P4MEDIUMCVSS 5.5fixed in 15.42026-06-11
CVE-2025-30459 [MEDIUM] CWE-359 CVE-2025-30459: A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
nvd
Apple macOS vulnerabilities | cvebase