Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 159 of 172
CVE-2022-0696P4MEDIUMCVSS 5.5fixed in 13.02022-02-21
CVE-2022-0696 [MEDIUM] CWE-476 CVE-2022-0696: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
nvd
CVE-2022-1420P4MEDIUMCVSS 5.5fixed in 13.02022-04-21
CVE-2022-1420 [MEDIUM] CWE-823 CVE-2022-1420: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
nvd
CVE-2019-8839P4MEDIUMCVSS 5.5≥ unspecified, < 10.152020-10-27
CVE-2019-8839 [MEDIUM] CWE-120 CVE-2019-8839: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An attacker in a privileged position may be able to perform a denial of service attack.
nvd
CVE-2023-42854P4MEDIUMCVSS 5.5≥ 12.0, < 12.7.1≥ 13.0, < 13.6.1+4 more2023-10-25
CVE-2023-42854 [MEDIUM] CVE-2023-42854: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.1,
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to cause a denial-of-service to Endpoint Security clients.
nvd
CVE-2019-8507P4MEDIUMCVSS 5.5≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8507 [MEDIUM] CWE-20 CVE-2019-8507: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.4. Processing malicious data may lead to unexpected application termination.
nvd
CVE-2024-23201P4MEDIUMCVSS 5.5≥ 12.0, < 12.7.4≥ 13.0, < 13.6.5+4 more2024-03-08
CVE-2024-23201 [MEDIUM] CWE-276 CVE-2024-23201: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43355P4MEDIUMCVSS 5.5≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43355 [MEDIUM] CWE-843 CVE-2025-43355: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43295P4MEDIUMCVSS 5.5≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43295 [MEDIUM] CWE-400 CVE-2025-43295: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 an
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to cause a denial-of-service.
nvd
CVE-2025-43299P4MEDIUMCVSS 5.5≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43299 [MEDIUM] CWE-20 CVE-2025-43299: A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 an
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to cause a denial-of-service.
nvd
CVE-2023-38593P4MEDIUMCVSS 5.5fixed in 11.7.9≥ 12.0, < 12.6.8+4 more2023-07-27
CVE-2023-38593 [MEDIUM] CVE-2023-38593: A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, iOS 16.6 and iPadOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to cause a denial-of-service.
nvd
CVE-2024-23237P4MEDIUMCVSS 5.5fixed in 15.0fixed in 152024-09-17
CVE-2024-23237 [MEDIUM] CVE-2024-23237: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An a
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause a denial-of-service.
nvd
CVE-2025-31202P4MEDIUMCVSS 5.5fixed in 15.42025-04-29
CVE-2025-31202 [MEDIUM] CWE-476 CVE-2025-31202: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2025-24165P4MEDIUMCVSS 5.5≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2026-06-11
CVE-2025-24165 [MEDIUM] CWE-284 CVE-2025-24165: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
nvd
CVE-2022-32895P4MEDIUMCVSS 4.7fixed in 13.0≥ unspecified, < 132022-11-01
CVE-2022-32895 [MEDIUM] CWE-362 CVE-2022-32895: A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13
A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system.
nvd
CVE-2024-23239P4MEDIUMCVSS 4.7≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23239 [MEDIUM] CWE-362 CVE-2024-23239: A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to leak sensitive user information.
nvd
CVE-2019-8769P4MEDIUMCVSS 4.3≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8769 [MEDIUM] CVE-2019-8769: An issue existed in the drawing of web page elements. The issue was addressed with improved logic. T
An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.
nvd
CVE-2023-27952P4MEDIUMCVSS 4.7fixed in 13.3≥ unspecified, < 13.32023-05-08
CVE-2023-27952 [MEDIUM] CWE-362 CVE-2023-27952: A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An
A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.
nvd
CVE-2023-41997P4MEDIUMCVSS 4.6≥ 14.0, < 14.1≥ unspecified, < 14.12023-10-25
CVE-2023-41997 [MEDIUM] CVE-2023-41997: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2023-41982P4MEDIUMCVSS 4.6≥ 14.0, < 14.1≥ unspecified, < 14.12023-10-25
CVE-2023-41982 [MEDIUM] CVE-2023-41982: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2024-23275P4MEDIUMCVSS 4.7≥ 12.0.0, < 12.7.4≥ 13.0, < 13.6.5+4 more2024-03-08
CVE-2024-23275 [MEDIUM] CWE-362 CVE-2024-23275: A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.
A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access protected user data.
nvd