cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 151 of 172
CVE-2021-1778P4MEDIUMCVSS 5.5≥ 11.0, < 11.2≥ unspecified, < 11.2+2 more2021-04-02
CVE-2021-1778 [MEDIUM] CWE-125 CVE-2021-1778: An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds check An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2019-8589P4MEDIUMCVSS 5.5≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8589 [MEDIUM] CVE-2019-8589: This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.5. A malici This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.5. A malicious application may bypass Gatekeeper checks.
nvd
CVE-2020-27894P4MEDIUMCVSS 5.5≥ 11.0, < 11.0.1≥ unspecified, < 11.02020-12-08
CVE-2020-27894 [MEDIUM] CVE-2020-27894: The issue was addressed with additional user controls. This issue is fixed in macOS Big Sur 11.0.1. The issue was addressed with additional user controls. This issue is fixed in macOS Big Sur 11.0.1. Users may be unable to remove metadata indicating where files were downloaded from.
nvd
CVE-2025-24123P4MEDIUMCVSS 5.5fixed in 13.7.3≥ 14.0, < 14.7.3+3 more2025-01-27
CVE-2025-24123 [MEDIUM] CVE-2025-24123: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected app termination.
nvd
CVE-2023-32422P4MEDIUMCVSS 5.5≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32422 [MEDIUM] CVE-2023-32422: This issue was addressed by adding additional SQLite logging restrictions. This issue is fixed in iO This issue was addressed by adding additional SQLite logging restrictions. This issue is fixed in iOS 16.5 and iPadOS 16.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-22644P4MEDIUMCVSS 5.5≥ 12.0, < 12.3≥ unspecified, < 12.32022-03-18
CVE-2022-22644 [MEDIUM] CVE-2022-22644: A privacy issue existed in the handling of Contact cards. This was addressed with improved state man A privacy issue existed in the handling of Contact cards. This was addressed with improved state management. This issue is fixed in macOS Monterey 12.3. A malicious application may be able to access information about a user's contacts.
nvd
CVE-2020-9851P4MEDIUMCVSS 5.5≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9851 [MEDIUM] CVE-2020-9851: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catali An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to modify protected parts of the file system.
nvd
CVE-2024-44169P4MEDIUMCVSS 5.5≥ 13.0, < 13.7≥ 14.0, < 14.7+3 more2024-09-17
CVE-2024-44169 [MEDIUM] CWE-400 CVE-2024-44169: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to cause unexpected system termination.
nvd
CVE-2024-44283P4MEDIUMCVSS 5.5≥ 13.0, < 13.7.1≥ 14.0, < 14.7.1+3 more2024-10-28
CVE-2024-44283 [MEDIUM] CWE-125 CVE-2024-44283: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequ An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsing a maliciously crafted file may lead to an unexpected app termination.
nvd
CVE-2024-44237P4MEDIUMCVSS 5.5≥ 13.0, < 13.7.1≥ 14.0, < 14.7.1+3 more2024-10-28
CVE-2024-44237 [MEDIUM] CWE-787 CVE-2024-44237: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in ma An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2024-27844P4MEDIUMCVSS 5.5≥ 14.0, < 14.5fixed in 14.52024-06-10
CVE-2024-27844 [MEDIUM] CVE-2024-27844: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A website's permission dialog may persist after navigation away from the site.
nvd
CVE-2024-27869P4MEDIUMCVSS 5.5fixed in 15.0fixed in 152024-09-17
CVE-2024-27869 [MEDIUM] CWE-22 CVE-2024-27869: The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Seq The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to record the screen without an indicator.
nvd
CVE-2024-44160P4MEDIUMCVSS 5.5≥ 13.0, < 13.7≥ 14.0, < 14.7+3 more2024-09-17
CVE-2024-44160 [MEDIUM] CWE-120 CVE-2024-44160: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Se A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. Processing a maliciously crafted texture may lead to unexpected app termination.
nvd
CVE-2024-27886P4MEDIUMCVSS 5.5≥ 14.0, < 14.4fixed in 13.7+1 more2024-07-29
CVE-2024-27886 [MEDIUM] CWE-783 CVE-2024-27886: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, ma A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Ventura 13.7. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.
nvd
CVE-2025-24235P4MEDIUMCVSS 5.5≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24235 [MEDIUM] CWE-400 CVE-2025-24235: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A remote attacker may be able to cause unexpected app termination or heap corruption.
nvd
CVE-2020-9885P4MEDIUMCVSS 5.5≥ unspecified, < macOS Catalina 10.15.62020-10-16
CVE-2020-9885 [MEDIUM] CWE-345 CVE-2020-9885: An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verifi An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an iMessage group could rejoin the group.
nvd
CVE-2024-44192P4MEDIUMCVSS 5.5fixed in 15.0fixed in 152025-03-10
CVE-2024-44192 [MEDIUM] CWE-400 CVE-2024-44192: The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18 The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2023-40449P4MEDIUMCVSS 5.5≥ 12.0.0, < 12.7.1≥ 13.0, < 13.6.1+4 more2023-10-25
CVE-2023-40449 [MEDIUM] CWE-119 CVE-2023-40449: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. An app may be able to cause a denial-of-service.
nvd
CVE-2024-44234P4MEDIUMCVSS 5.5fixed in 13.7.1≥ 14.0, < 14.7.1+2 more2024-11-01
CVE-2024-44234 [MEDIUM] CWE-120 CVE-2024-44234: The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17 The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Parsing a maliciously crafted video file may lead to unexpected system termination.
nvd
CVE-2020-3839P4MEDIUMCVSS 5.5≥ unspecified, < macOS Catalina 10.15.32020-02-27
CVE-2020-3839 [MEDIUM] CWE-20 CVE-2020-3839: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Cata A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory.
nvd
Apple macOS vulnerabilities | cvebase