cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 161 of 172
CVE-2023-42952P4MEDIUMCVSS 4.4≥ 12.0, < 12.7.1≥ 13.0, < 13.6.3+4 more2024-02-21
CVE-2023-42952 [MEDIUM] CWE-269 CVE-2023-42952: The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.
nvd
CVE-2025-43493P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43493 [MEDIUM] CWE-290 CVE-2025-43493: The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPa The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2022-42807P4MEDIUMCVSS 4.3fixed in 13.0≥ unspecified, < 132023-06-23
CVE-2022-42807 [MEDIUM] CWE-640 CVE-2022-42807: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key
nvd
CVE-2023-28208P4MEDIUMCVSS 4.3≥ 13.0, < 13.2≥ unspecified, < 13.22023-09-06
CVE-2023-28208 [MEDIUM] CVE-2023-28208: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may send a text from a secondary eSIM despite configuring a contact to use a primary eSIM.
nvd
CVE-2026-28971P4MEDIUMCVSS 4.3≥ 26.0, < 26.5fixed in 26.52026-05-11
CVE-2026-28971 [MEDIUM] CWE-1021 CVE-2026-28971: The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.
nvd
CVE-2026-39869P4MEDIUMCVSS 4.3≥ 14.0, < 14.8.7≥ 15.0, < 15.7.7+4 more2026-05-11
CVE-2026-39869 [MEDIUM] CWE-120 CVE-2026-39869: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file may terminate the process.
nvd
CVE-2026-20691P4MEDIUMCVSS 4.3≥ 26.0, < 26.4fixed in 26.42026-03-25
CVE-2026-20691 [MEDIUM] CWE-497 CVE-2026-20691: An authorization issue was addressed with improved state management. This issue is fixed in Safari 2 An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2025-46299P4MEDIUMCVSS 4.3fixed in 26.22026-01-09
CVE-2025-46299 [MEDIUM] CWE-284 CVE-2025-46299: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Sa A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
nvd
CVE-2019-8538P4MEDIUMCVSS 5.5≥ unspecified, < 10.14≥ unspecified, < 5.22020-10-27
CVE-2019-8538 [MEDIUM] CVE-2019-8538: A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2 A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. Processing a maliciously crafted vcf file may lead to a denial of service.
nvd
CVE-2022-32827P4MEDIUMCVSS 5.5fixed in 13.0≥ unspecified, < 13+1 more2022-11-01
CVE-2022-32827 [MEDIUM] CWE-787 CVE-2022-32827: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to cause a denial-of-service.
nvd
CVE-2025-24199P4MEDIUMCVSS 5.5≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24199 [MEDIUM] CWE-400 CVE-2025-24199: An uncontrolled format string issue was addressed with improved input validation. This issue is fixe An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause a denial-of-service.
nvd
CVE-2023-32385P4MEDIUMCVSS 5.5fixed in 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32385 [MEDIUM] CWE-770 CVE-2023-32385: A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16 A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. Opening a PDF file may lead to unexpected app termination.
nvd
CVE-2022-26699P4MEDIUMCVSS 5.5≤ 9.0≥ 11.0, < 13.0+1 more2023-08-14
CVE-2022-26699 [MEDIUM] CVE-2022-26699: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to cause a denial-of-service to Endpoint Security clients.
nvd
CVE-2025-43235P4MEDIUMCVSS 5.5fixed in 15.62025-07-30
CVE-2025-43235 [MEDIUM] CWE-400 CVE-2025-43235: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.
nvd
CVE-2023-41979P4MEDIUMCVSS 4.7fixed in 14.0≥ unspecified, < 142023-09-27
CVE-2023-41979 [MEDIUM] CWE-362 CVE-2023-41979: A race condition was addressed with improved locking. This issue is fixed in macOS Sonoma 14. An app A race condition was addressed with improved locking. This issue is fixed in macOS Sonoma 14. An app may be able to modify protected parts of the file system.
nvd
CVE-2024-23293P4MEDIUMCVSS 4.6≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23293 [MEDIUM] CVE-2024-23293: This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2026-28992P4MEDIUMCVSS 4.7≥ 14.0, < 14.8.7≥ 15.0, < 15.7.7+4 more2026-05-11
CVE-2026-28992 [MEDIUM] CWE-362 CVE-2026-28992: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination.
nvd
CVE-2025-30439P4MEDIUMCVSS 4.6≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-30439 [MEDIUM] CWE-200 CVE-2025-30439: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2024-44137P4MEDIUMCVSS 4.6fixed in 13.7.1≥ 14.0, < 14.7.1+2 more2024-10-28
CVE-2024-44137 [MEDIUM] CWE-863 CVE-2024-44137: The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker with physical access may be able to share items from the lock screen.
nvd
CVE-2022-22621P4MEDIUMCVSS 4.6≥ 12.0, < 12.3≥ unspecified, < 12.32022-03-18
CVE-2022-22621 [MEDIUM] CVE-2022-22621: This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvd
Apple macOS vulnerabilities | cvebase