cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 157 of 172
CVE-2025-24112P4MEDIUMCVSS 5.5fixed in 14.7.3≥ 15.0, < 15.3+1 more2025-01-27
CVE-2025-24112 [MEDIUM] CWE-770 CVE-2025-24112: The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonom The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an unexpected app termination.
nvd
CVE-2025-43312P4MEDIUMCVSS 5.5≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43312 [MEDIUM] CWE-120 CVE-2025-43312: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to cause unexpected system termination.
nvd
CVE-2023-32400P4MEDIUMCVSS 5.5≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32400 [MEDIUM] CWE-281 CVE-2023-32400: This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watc This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
nvd
CVE-2025-24151P4MEDIUMCVSS 5.5fixed in 13.7.3≥ 14.0, < 14.7.3+3 more2025-01-27
CVE-2025-24151 [MEDIUM] CWE-400 CVE-2025-24151: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, ma The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2025-31226P4MEDIUMCVSS 5.5fixed in 15.52025-05-12
CVE-2025-31226 [MEDIUM] CWE-400 CVE-2025-31226: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, i A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted image may lead to a denial-of-service.
nvd
CVE-2026-28852P4MEDIUMCVSS 5.5≥ 15.0, < 15.7.5≥ 26.0, < 26.4+2 more2026-03-25
CVE-2026-28852 [MEDIUM] CWE-20 CVE-2026-28852: A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause a denial-of-service.
nvd
CVE-2025-24152P4MEDIUMCVSS 5.5fixed in 15.32025-01-27
CVE-2025-24152 [MEDIUM] CVE-2025-24152: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2023-28185P4MEDIUMCVSS 5.5≥ 11.0, < 11.7.5≥ 12.0.0, < 12.6.4+2 more2024-01-10
CVE-2023-28185 [MEDIUM] CWE-190 CVE-2023-28185: An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16. An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4, watchOS 9.4, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43353P4MEDIUMCVSS 5.5≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43353 [MEDIUM] CWE-787 CVE-2025-43353: The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7, macO The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. Processing a maliciously crafted string may lead to heap corruption.
nvd
CVE-2023-38607P4MEDIUMCVSS 5.5fixed in 14.0≥ unspecified, < 142024-01-10
CVE-2023-38607 [MEDIUM] CVE-2023-38607: The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14. An The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14. An app may be able to modify Printer settings.
nvd
CVE-2025-24184P4MEDIUMCVSS 5.5fixed in 15.32025-05-19
CVE-2025-24184 [MEDIUM] CVE-2025-24184: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.
nvd
CVE-2026-20602P4MEDIUMCVSS 5.5fixed in 14.8.4≥ 15.0, < 15.7.4+3 more2026-02-11
CVE-2026-20602 [MEDIUM] CWE-400 CVE-2026-20602: The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7. The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to cause a denial-of-service.
nvd
CVE-2026-43768P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-43768 [MEDIUM] CWE-400 CVE-2026-43768: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-20654P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20654 [MEDIUM] CWE-119 CVE-2026-20654: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64724P4MEDIUMCVSS 5.5≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-64724 [MEDIUM] CWE-400 CVE-2026-64724: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2026-43817P4MEDIUMCVSS 5.5≥ 26.0, < 26.6fixed in 26.62026-07-27
CVE-2026-43817 [MEDIUM] CWE-125 CVE-2026-43817: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-43806P4MEDIUMCVSS 5.5≥ 26.0, < 26.6fixed in 26.62026-07-27
CVE-2026-43806 [MEDIUM] CWE-400 CVE-2026-43806: A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macO A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cause a denial of service.
nvd
CVE-2025-43260P4MEDIUMCVSS 5.1fixed in 14.7.7≥ 15.0, < 15.6+1 more2025-07-30
CVE-2025-43260 [MEDIUM] CWE-266 CVE-2025-43260: This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, m This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.
nvd
CVE-2025-43266P4MEDIUMCVSS 5.1fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43266 [MEDIUM] CWE-732 CVE-2025-43266: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.
nvd
CVE-2025-43262P4MEDIUMCVSS 5.1fixed in 26.0fixed in 262025-09-15
CVE-2025-43262 [MEDIUM] CWE-358 CVE-2025-43262: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. USB Restricted Mode may not be applied to accessories connected during boot.
nvd
Apple macOS vulnerabilities | cvebase