cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 117 of 172
CVE-2020-9846P4MEDIUMCVSS 5.3fixed in 12.0.1≥ unspecified, < 12.02023-02-27
CVE-2020-9846 [MEDIUM] CWE-200 CVE-2020-9846: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to access local users' Apple IDs.
nvd
CVE-2022-29458P4HIGHCVSS 7.1fixed in 13.02022-04-18
CVE-2022-29458 [HIGH] CWE-125 CVE-2022-29458: ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_st ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
nvd
CVE-2025-43429P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43429 [MEDIUM] CWE-119 CVE-2025-43429: A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, i A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2022-26765P4MEDIUMCVSS 4.7≥ 12.0, < 12.42022-05-26
CVE-2022-26765 [MEDIUM] CWE-362 CVE-2022-26765: A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvO A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2020-9810P4MEDIUMCVSS 6.8≥ unspecified, < macOS Catalina 10.15.52020-10-22
CVE-2020-9810 [MEDIUM] CVE-2020-9810: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A person with physical access to a Mac may be able to bypass Login Window.
nvd
CVE-2020-10014P4MEDIUMCVSS 6.3fixed in 11.0.1≥ unspecified, < 11.02020-12-08
CVE-2020-10014 [MEDIUM] CWE-22 CVE-2020-10014: A parsing issue in the handling of directory paths was addressed with improved path validation. This A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to break out of its sandbox.
nvd
CVE-2019-8855P4MEDIUMCVSS 6.3≥ unspecified, < 10.152020-10-27
CVE-2019-8855 [MEDIUM] CVE-2019-8855: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Cat An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access restricted files.
nvd
CVE-2025-31235P4MEDIUMCVSS 6.5fixed in 13.7.6≥ 14.0, < 14.7.6+3 more2025-05-12
CVE-2025-31235 [MEDIUM] CWE-415 CVE-2025-31235: A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17. A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination.
nvd
CVE-2020-9939P4MEDIUMCVSS 6.4≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9939 [MEDIUM] CWE-367 CVE-2020-9939: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A loca This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to load unsigned kernel extensions.
nvd
CVE-2023-27940P4MEDIUMCVSS 6.3≥ 12.0.0, < 12.6.6≥ 13.0, < 13.4+2 more2023-06-23
CVE-2023-27940 [MEDIUM] CVE-2023-27940: The issue was addressed with additional permissions checks. This issue is fixed in iOS 15.7.6 and iP The issue was addressed with additional permissions checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, macOS Monterey 12.6.6, macOS Ventura 13.4. A sandboxed app may be able to observe system-wide network connections.
nvd
CVE-2020-9995P4MEDIUMCVSS 6.1≥ unspecified, < 5.112021-04-02
CVE-2020-9995 [MEDIUM] CWE-79 CVE-2020-9995: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL may lead to an open redirect or cross site scripting.
nvd
CVE-2025-31275P4MEDIUMCVSS 6.2fixed in 15.62025-07-30
CVE-2025-31275 [MEDIUM] CWE-274 CVE-2025-31275: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to launch any installed app.
nvd
CVE-2025-43238P4MEDIUMCVSS 6.2≥ 13.0, < 13.7.7≥ 14.0, < 14.7.7+4 more2026-04-02
CVE-2025-43238 [MEDIUM] CWE-190 CVE-2025-43238: An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequo An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.
nvd
CVE-2026-28977P4MEDIUMCVSS 6.2≥ 14.0, < 14.8.7≥ 15.0, < 15.7.7+4 more2026-05-11
CVE-2026-28977 [MEDIUM] CWE-119 CVE-2026-28977: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2022-22600P4MEDIUMCVSS 5.5fixed in 12.3≥ unspecified, < 12.32022-03-18
CVE-2022-22600 [MEDIUM] CVE-2022-22600: The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2020-27896P4MEDIUMCVSS 5.5≥ 11.0, < 11.0.1≥ unspecified, < 11.02020-12-08
CVE-2020-27896 [MEDIUM] CWE-22 CVE-2020-27896: A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 1 A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to modify the file system.
nvd
CVE-2019-8582P4MEDIUMCVSS 5.5≥ unspecified, < 10.14≥ unspecified, < 12.3+2 more2020-10-27
CVE-2019-8582 [MEDIUM] CWE-125 CVE-2019-8582: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2019-8789P4MEDIUMCVSS 5.5≥ unspecified, < macOS Catalina 10.15.12019-12-18
CVE-2019-8789 [MEDIUM] CWE-59 CVE-2019-8789: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information.
nvd
CVE-2021-1791P4MEDIUMCVSS 5.5≥ 11.0, < 11.2≥ unspecified, < 11.2+2 more2021-04-02
CVE-2021-1791 [MEDIUM] CWE-125 CVE-2021-1791: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to disclose kernel memory
nvd
CVE-2020-9974P4MEDIUMCVSS 5.5≥ unspecified, < 11.02020-12-08
CVE-2020-9974 [MEDIUM] CVE-2020-9974: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A malicious application may be able to determine kernel memory layout.
nvd
Apple macOS vulnerabilities | cvebase