cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 162 of 172
CVE-2025-43259P4MEDIUMCVSS 4.6fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43259 [MEDIUM] CWE-359 CVE-2025-43259: This issue was addressed with improved redaction of sensitive information. This issue is fixed in ma This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2019-8550P4MEDIUMCVSS 4.3≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8550 [MEDIUM] CWE-459 CVE-2019-8550: An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the call is ringing.
nvd
CVE-2019-8670P4MEDIUMCVSS 4.3≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8670 [MEDIUM] CWE-20 CVE-2019-8670: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2026-20662P4MEDIUMCVSS 4.6fixed in 15.7.4≥ 26.0, < 26.3+1 more2026-02-11
CVE-2026-20662 [MEDIUM] CWE-200 CVE-2026-20662: An authorization issue was addressed with improved state management. This issue is fixed in macOS Se An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
nvd
CVE-2021-1861P4MEDIUMCVSS 4.3≥ 11.0, < 11.3≥ unspecified, < 11.32021-09-08
CVE-2021-1861 [MEDIUM] CVE-2021-1861: An issue existed in determining cache occupancy. The issue was addressed through improved logic. Thi An issue existed in determining cache occupancy. The issue was addressed through improved logic. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to track users by setting state in a cache.
nvd
CVE-2020-9857P4MEDIUMCVSS 4.3≥ unspecified, < 10.152020-10-27
CVE-2020-9857 [MEDIUM] CVE-2020-9857: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5, Security Update 2020-003 Mojave, Security Update 2020-003 High Sierra. A malicious website may be able to exfiltrate autofilled data in Safari.
nvd
CVE-2020-9935P4MEDIUMCVSS 4.3≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9935 [MEDIUM] CVE-2020-9935: A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10 A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6. A user may be unexpectedly logged in to another user’s account.
nvd
CVE-2023-41977P4MEDIUMCVSS 4.3≥ 14.0, < 14.1≥ unspecified, < 14.12023-10-25
CVE-2023-41977 [MEDIUM] CVE-2023-41977: The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, iOS 16.7.2 and iPadOS 16.7.2. Visiting a malicious website may reveal browsing history.
nvd
CVE-2023-42438P4MEDIUMCVSS 4.3≥ 14.0, < 14.1≥ unspecified, < 14.12023-10-25
CVE-2023-42438 [MEDIUM] CVE-2023-42438: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. Visiting a malicious website may lead to user interface spoofing.
nvd
CVE-2022-22677P4MEDIUMCVSS 4.3≥ 12.0.0, < 12.4≥ unspecified, < 12.4+1 more2022-11-01
CVE-2022-22677 [MEDIUM] CVE-2022-22677: A logic issue in the handling of concurrent media was addressed with improved state handling. This i A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.
nvd
CVE-2023-40388P4MEDIUMCVSS 4.3fixed in 14.0≥ unspecified, < 142023-09-27
CVE-2023-40388 [MEDIUM] CVE-2023-40388: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macO A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. Safari may save photos to an unprotected location.
nvd
CVE-2021-30718P4MEDIUMCVSS 4.3≥ 11.0, < 11.4≥ unspecified, < 11.42021-09-08
CVE-2021-30718 [MEDIUM] CVE-2021-30718: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A non-priv This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A non-privileged user may be able to modify restricted settings.
nvd
CVE-2025-24128P4MEDIUMCVSS 4.3fixed in 15.32025-01-27
CVE-2025-24128 [MEDIUM] CVE-2025-24128: The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2023-40425P4MEDIUMCVSS 4.4≥ 12.0.0, < 12.7.1≥ unspecified, < 14+1 more2023-10-25
CVE-2023-40425 [MEDIUM] CWE-532 CVE-2023-40425: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14, macOS Monterey 12.7.1. An app with root privileges may be able to access private information.
nvd
CVE-2022-32781P4MEDIUMCVSS 4.4fixed in 10.15.7≥ 11.0, < 11.6.8+6 more2022-09-23
CVE-2022-32781 [MEDIUM] CWE-269 CVE-2022-32781: This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, i This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8. An app with root privileges may be able to access private information.
nvd
CVE-2025-24242P4MEDIUMCVSS 4.4fixed in 15.42025-03-31
CVE-2025-24242 [MEDIUM] CWE-59 CVE-2025-24242: This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.
nvd
CVE-2024-44130P4MEDIUMCVSS 4.4fixed in 15.0fixed in 152024-09-17
CVE-2024-44130 [MEDIUM] CVE-2024-44130: This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15. An This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15. An app with root privileges may be able to access private information.
nvd
CVE-2024-40825P4MEDIUMCVSS 4.4fixed in 15.0fixed in 152024-09-17
CVE-2024-40825 [MEDIUM] CWE-284 CVE-2024-40825: The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15, visionOS 2. A malicious app with root privileges may be able to modify the contents of system files.
nvd
CVE-2025-43310P4MEDIUMCVSS 4.4≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43310 [MEDIUM] CWE-359 CVE-2025-43310: A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequo A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to trick a user into copying sensitive data to the pasteboard.
nvd
CVE-2026-20603P4MEDIUMCVSS 4.4fixed in 26.32026-02-11
CVE-2026-20603 [MEDIUM] CWE-284 CVE-2026-20603: This issue was addressed with improved redaction of sensitive information. This issue is fixed in ma This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An app with root privileges may be able to access private information.
nvd
Apple macOS vulnerabilities | cvebase