cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 167 of 172
CVE-2023-42969P4LOWCVSS 3.3fixed in 12.7≥ 13.0, < 13.6+3 more2025-04-11
CVE-2023-42969 [LOW] CWE-284 CVE-2023-42969: An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16. An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. The issue was addressed with improved handling of caches.
nvd
CVE-2024-44210P4LOWCVSS 3.3≥ 15.0, < 15.1fixed in 15.12026-01-16
CVE-2024-44210 [LOW] CWE-284 CVE-2024-44210: This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15 This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.
nvd
CVE-2025-43516P4LOWCVSS 3.3fixed in 14.8.3≥ 15.0, < 15.7.3+2 more2025-12-12
CVE-2025-43516 [LOW] CWE-384 CVE-2025-43516: A session management issue was addressed with improved checks. This issue is fixed in macOS Sequoia A session management issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. A user with Voice Control enabled may be able to transcribe another user's activity.
nvd
CVE-2025-43328P4LOWCVSS 3.3fixed in 26.0fixed in 262025-09-15
CVE-2025-43328 [LOW] CWE-284 CVE-2025-43328: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
nvd
CVE-2025-43404P4LOWCVSS 3.3fixed in 26.12025-12-12
CVE-2025-43404 [LOW] CWE-284 CVE-2025-43404: A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
nvd
CVE-2026-20684P4LOWCVSS 3.3≥ 26.0, < 26.4fixed in 26.42026-03-25
CVE-2026-20684 [LOW] CWE-284 CVE-2026-20684: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.
nvd
CVE-2026-28893P4LOWCVSS 3.3≥ 26.0, < 26.4fixed in 26.42026-03-25
CVE-2026-28893 [LOW] CVE-2026-28893: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macO A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A document may be written to a temporary file when using print preview.
nvd
CVE-2026-20646P4LOWCVSS 3.3fixed in 26.32026-02-11
CVE-2026-20646 [LOW] CWE-532 CVE-2026-20646: A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.
nvd
CVE-2025-43522P4LOWCVSS 3.3fixed in 15.7.3fixed in 26.22025-12-12
CVE-2025-43522 [LOW] CWE-347 CVE-2025-43522: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing res A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to access user-sensitive data.
nvd
CVE-2025-43349P4LOWCVSS 2.8≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43349 [LOW] CWE-787 CVE-2025-43349: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted video file may lead to unexpected app termination.
nvd
CVE-2021-30803P4LOWCVSS 3.3≥ 11.0, < 11.5≥ unspecified, < 11.52021-09-08
CVE-2021-30803 [LOW] CVE-2021-30803: A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11. A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access a user’s recent Contacts.
nvd
CVE-2021-31000P4LOWCVSS 3.3≥ 12.0.0, < 12.12021-08-24
CVE-2021-31000 [LOW] CWE-276 CVE-2021-31000: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPad A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1, tvOS 15.2. A malicious application may be able to read sensitive contact information.
nvd
CVE-2021-30994P4LOWCVSS 3.3v12.0.0≥ unspecified, < 12.02021-08-24
CVE-2021-30994 [LOW] CVE-2021-30994: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monter An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to access local users' Apple IDs.
nvd
CVE-2021-30671P4LOWCVSS 3.3≥ 11.0, < 11.4≥ unspecified, < 11.4+1 more2021-09-08
CVE-2021-30671 [LOW] CWE-20 CVE-2021-30671: A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Sec A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A malicious application may be able to send unauthorized Apple events to Finder.
nvd
CVE-2024-23245P4LOWCVSS 3.3≥ 12.0, < 12.7.4≥ 13.0, < 13.6.5+4 more2024-03-08
CVE-2024-23245 [LOW] CVE-2024-23245: This issue was addressed by adding an additional prompt for user consent. This issue is fixed in mac This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without user consent.
nvd
CVE-2024-23211P4LOWCVSS 3.3≥ 14.0, < 14.3fixed in 14.32024-01-23
CVE-2024-23211 [LOW] CWE-359 CVE-2024-23211: A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Saf A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A user's private browsing activity may be visible in Settings.
nvd
CVE-2023-28197P4LOWCVSS 3.3fixed in 11.7.5≥ 12.0.0, < 12.6.4+4 more2024-01-10
CVE-2023-28197 [LOW] CWE-284 CVE-2023-28197: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ven An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS Monterey 12.6.4. An app may be able to access user-sensitive data.
nvd
CVE-2020-29623P4LOWCVSS 3.3≥ 11.0, < 11.1.0≥ unspecified, < 11.12021-04-02
CVE-2020-29623 [LOW] CVE-2020-29623: "Clear History and Website Data" did not clear the history. The issue was addressed with improved da "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.
nvd
CVE-2023-41065P4LOWCVSS 3.3fixed in 14.0≥ unspecified, < 142023-09-27
CVE-2023-41065 [LOW] CVE-2023-41065: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to read sensitive location information.
nvd
CVE-2025-46279P4LOWCVSS 3.3fixed in 26.22025-12-17
CVE-2025-46279 [LOW] CWE-200 CVE-2025-46279: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 an A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.
nvd
Apple macOS vulnerabilities | cvebase