Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 163 of 172
CVE-2022-32857P4MEDIUMCVSS 4.3fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-08-24
CVE-2022-32857 [MEDIUM] CWE-319 CVE-2022-32857: This issue was addressed by using HTTPS when sending information over the network. This issue is fix
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a user’s activity.
nvd
CVE-2024-54568P4MEDIUMCVSS 4.3≥ 15.0, < 15.2fixed in 15.22025-08-29
CVE-2024-54568 [MEDIUM] CWE-120 CVE-2024-54568: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Pa
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an unexpected app termination.
nvd
CVE-2025-43374P4MEDIUMCVSS 4.3fixed in 13.7.3≥ 14.0, < 14.7.3+3 more2025-11-21
CVE-2025-43374 [MEDIUM] CWE-121 CVE-2025-43374: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory.
nvd
CVE-2025-43265P4MEDIUMCVSS 4.0fixed in 15.62025-07-30
CVE-2025-43265 [MEDIUM] CWE-125 CVE-2025-43265: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.
nvd
CVE-2019-8842P4LOWCVSS 3.3≥ unspecified, < 10.152020-10-27
CVE-2019-8842 [LOW] CWE-120 CVE-2019-8842: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs.
nvd
CVE-2022-1674P4MEDIUMCVSS 5.5fixed in 13.02022-05-12
CVE-2022-1674 [MEDIUM] CWE-476 CVE-2022-1674: NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vi
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
nvd
CVE-2023-40422P4MEDIUMCVSS 5.5fixed in 14.0≥ unspecified, < 142023-09-27
CVE-2023-40422 [MEDIUM] CVE-2023-40422: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An ap
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to cause a denial-of-service.
nvd
CVE-2024-44231P4MEDIUMCVSS 4.6v15.0fixed in 15.12024-12-20
CVE-2024-44231 [MEDIUM] CVE-2024-44231: This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with physical access to a Mac may be able to bypass Login Window during a software update.
nvd
CVE-2026-43743P4MEDIUMCVSS 4.7≥ 26.0, < 26.5.2fixed in 26.5.22026-06-29
CVE-2026-43743 [MEDIUM] CWE-362 CVE-2026-43743: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and i
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2022-32935P4MEDIUMCVSS 4.6fixed in 13.0≥ unspecified, < 13+2 more2022-11-01
CVE-2022-32935 [MEDIUM] CWE-287 CVE-2022-32935: A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.
nvd
CVE-2023-32391P4MEDIUMCVSS 4.6≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32391 [MEDIUM] CWE-125 CVE-2023-32391: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, w
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. A shortcut may be able to use sensitive data with certain actions without prompting the user.
nvd
CVE-2022-22647P4MEDIUMCVSS 4.6≥ 11.6, < 11.6.5≥ 12.0, < 12.3+4 more2022-03-18
CVE-2022-22647 [MEDIUM] CVE-2022-22647: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Mo
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A person with access to a Mac may be able to bypass Login Window.
nvd
CVE-2024-44223P4MEDIUMCVSS 4.6v15.0fixed in 15.12024-12-20
CVE-2024-44223 [MEDIUM] CWE-281 CVE-2024-44223: This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.
nvd
CVE-2023-28322P4LOWCVSS 3.7≥ 11.0, < 11.7.9≥ 12.0, < 12.6.8+1 more2023-05-26
CVE-2023-28322 [LOW] CWE-200 CVE-2023-28322: An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surp
nvd
CVE-2021-1824P4MEDIUMCVSS 4.4≥ 11.0, < 11.3≥ unspecified, < 11.3+1 more2021-09-08
CVE-2021-1824 [MEDIUM] CVE-2021-1824: This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.3, Secu
This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application with root privileges may be able to access private information.
nvd
CVE-2024-27882P4MEDIUMCVSS 4.4fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-27882 [MEDIUM] CVE-2024-27882: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Montere
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
nvd
CVE-2025-24136P4MEDIUMCVSS 4.4fixed in 13.7.3≥ 14.0, < 14.7.3+3 more2025-01-27
CVE-2025-24136 [MEDIUM] CWE-59 CVE-2025-24136: This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious app may be able to create symlinks to protected regions of the disk.
nvd
CVE-2024-27883P4MEDIUMCVSS 4.4fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-27883 [MEDIUM] CWE-732 CVE-2024-27883: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Montere
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
nvd
CVE-2024-40834P4MEDIUMCVSS 4.4≤ 12.7.6≥ 13.0, ≤ 13.6.8+4 more2024-07-29
CVE-2024-40834 [MEDIUM] CWE-862 CVE-2024-40834: This issue was addressed by adding an additional prompt for user consent. This issue is fixed in mac
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to bypass sensitive Shortcuts app settings.
nvd
CVE-2022-32782P4MEDIUMCVSS 4.4≥ 12.0, < 12.4≥ unspecified, < 12.42022-09-23
CVE-2022-32782 [MEDIUM] CWE-269 CVE-2022-32782: This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. A
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.
nvd