Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 109 of 172
CVE-2025-43468P4MEDIUMCVSS 5.5fixed in 14.8.2≥ 15.0, < 15.7.2+2 more2025-11-04
CVE-2025-43468 [MEDIUM] CWE-347 CVE-2025-43468: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing res
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2025-43339P4MEDIUMCVSS 5.5fixed in 26.12026-06-11
CVE-2025-43339 [MEDIUM] CWE-284 CVE-2025-43339: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tah
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.
nvd
CVE-2026-43665P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+2 more2026-07-27
CVE-2026-43665 [MEDIUM] CWE-862 CVE-2026-43665: This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.
nvd
CVE-2023-42981P4MEDIUMCVSS 5.4v14.0≥ unspecified, < 142025-04-11
CVE-2023-42981 [MEDIUM] CWE-20 CVE-2023-42981: Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issu
Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.
nvd
CVE-2023-42836P4MEDIUMCVSS 5.3≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-02-21
CVE-2023-42836 [MEDIUM] CVE-2023-42836: A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, m
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An attacker may be able to access connected network volumes mounted in the home directory.
nvd
CVE-2022-32933P4MEDIUMCVSS 5.3fixed in 12.5≥ unspecified, < 12.52024-06-10
CVE-2022-32933 [MEDIUM] CWE-200 CVE-2022-32933: An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed i
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode.
nvd
CVE-2025-24140P4MEDIUMCVSS 5.3fixed in 15.32025-01-27
CVE-2025-24140 [MEDIUM] CWE-276 CVE-2025-24140: This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the quarantine flag applied.
nvd
CVE-2026-43704P4MEDIUMCVSS 5.3fixed in 26.5.22026-06-29
CVE-2026-43704 [MEDIUM] CWE-416 CVE-2026-43704: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash.
nvd
CVE-2024-44212P4MEDIUMCVSS 5.3fixed in 15.12024-12-12
CVE-2024-44212 [MEDIUM] CWE-346 CVE-2024-44212: A cookie management issue was addressed with improved state management. This issue is fixed in Safar
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.
nvd
CVE-2025-46308P4MEDIUMCVSS 5.3fixed in 15.42026-06-11
CVE-2025-46308 [MEDIUM] CWE-284 CVE-2025-46308: An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.
nvd
CVE-2026-20676P4MEDIUMCVSS 5.3fixed in 26.32026-02-11
CVE-2026-20676 [MEDIUM] CWE-400 CVE-2026-20676: This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.
nvd
CVE-2025-24097P4MEDIUMCVSS 5.0fixed in 14.7.5fixed in 15.42025-03-31
CVE-2025-24097 [MEDIUM] CWE-125 CVE-2025-24097: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to read arbitrary file metadata.
nvd
CVE-2026-20693P4MEDIUMCVSS 4.9≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-20693 [MEDIUM] CWE-732 CVE-2026-20693: This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An attacker with root privileges may be able to delete protected system files.
nvd
CVE-2017-13907P4MEDIUMCVSS 6.8≥ unspecified, < 10.132021-12-23
CVE-2017-13907 [MEDIUM] CVE-2017-13907: A state management issue was addressed with improved state validation. This issue is fixed in macOS
A state management issue was addressed with improved state validation. This issue is fixed in macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan. The screen lock may unexpectedly remain unlocked.
nvd
CVE-2025-24198P4MEDIUMCVSS 6.6≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24198 [MEDIUM] CWE-284 CVE-2025-24198: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2021-30866P4MEDIUMCVSS 6.5fixed in 12.0.12021-08-24
CVE-2021-30866 [MEDIUM] CVE-2021-30866: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvO
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A device may be passively tracked by its WiFi MAC address.
nvd
CVE-2025-24251P4MEDIUMCVSS 6.5fixed in 13.7.5≥ 14.0, < 14.7.5+3 more2025-04-29
CVE-2025-24251 [MEDIUM] CWE-476 CVE-2025-24251: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may cause an unexpected app termination.
nvd
CVE-2025-30445P4MEDIUMCVSS 6.5fixed in 13.7.5≥ 14.0, < 14.7.5+3 more2025-04-29
CVE-2025-30445 [MEDIUM] CWE-843 CVE-2025-30445: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadO
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.
nvd
CVE-2025-31203P4MEDIUMCVSS 6.5fixed in 14.7.5≥ 15.0, < 15.4+1 more2025-04-29
CVE-2025-31203 [MEDIUM] CWE-190 CVE-2025-31203: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 an
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2021-30783P4MEDIUMCVSS 6.5≥ 11.0, < 11.5≥ unspecified, < 11.5+1 more2021-09-08
CVE-2021-30783 [MEDIUM] CVE-2021-30783: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Su
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A sandboxed process may be able to circumvent sandbox restrictions.
nvd