Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL204HIGH1438MEDIUM1494LOW151UNKNOWN151
Vulnerabilities
Page 17 of 172
CVE-2019-8680P3HIGHCVSS 8.8≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8680 [HIGH] CWE-787 CVE-2019-8680: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8644P3HIGHCVSS 8.8≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8644 [HIGH] CWE-416 CVE-2019-8644: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-32845P3CRITICALCVSS 10.0≥ 12.0, < 12.5≥ unspecified, < 12.52022-09-23
CVE-2022-32845 [CRITICAL] CWE-693 CVE-2022-32845: This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPad
This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.
nvd
CVE-2022-42795P3HIGHCVSS 8.8fixed in 13.0≥ unspecified, < 13+1 more2022-11-01
CVE-2022-42795 [HIGH] CWE-787 CVE-2022-42795: A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-3970P3HIGHCVSS 8.8fixed in 13.52022-11-13
CVE-2022-3970 [HIGH] CWE-189 CVE-2022-3970: A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f
nvd
CVE-2022-22624P3HIGHCVSS 8.8≥ 12.0, < 12.32022-09-23
CVE-2022-22624 [HIGH] CWE-416 CVE-2022-22624: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-42950P3HIGHCVSS 8.8≥ 14.0, < 14.2≥ unspecified, < 14.22024-03-28
CVE-2023-42950 [HIGH] CWE-416 CVE-2023-42950: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2020-3878P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.52020-02-27
CVE-2020-3878 [HIGH] CWE-125 CVE-2020-3878: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2023-28198P3HIGHCVSS 8.8≥ 13.0, < 13.3≥ unspecified, < 13.32023-08-14
CVE-2023-28198 [HIGH] CWE-416 CVE-2023-28198: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
nvd
CVE-2022-42826P3HIGHCVSS 8.8fixed in 13.0≥ unspecified, < 13+1 more2023-02-27
CVE-2022-42826 [HIGH] CWE-416 CVE-2022-42826: A use after free issue was addressed with improved memory management. This issue is fixed in macOS V
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-6203P3CRITICALCVSS 9.8≥ unspecified, < macOS Mojave 10.14.42020-04-17
CVE-2019-6203 [CRITICAL] CVE-2019-6203: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.
nvd
CVE-2020-8285P3HIGHCVSS 7.5≥ 11.0, < 11.32020-12-14
CVE-2020-8285 [HIGH] CWE-674 CVE-2020-8285: curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
nvd
CVE-2024-27859P3HIGHCVSS 8.8fixed in 14.42025-02-10
CVE-2024-27859 [HIGH] CWE-94 CVE-2024-27859: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.
nvd
CVE-2023-42970P3HIGHCVSS 8.8fixed in 14.0≥ unspecified, < 142025-04-11
CVE-2023-42970 [HIGH] CWE-416 CVE-2023-42970: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.
nvd
CVE-2019-8716P3CRITICALCVSS 9.8≥ unspecified, < 10.152020-10-27
CVE-2019-8716 [CRITICAL] CWE-787 CVE-2019-8716: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2022-0318P3CRITICALCVSS 9.8fixed in 13.02022-01-21
CVE-2022-0318 [CRITICAL] CWE-122 CVE-2022-0318: Heap-based Buffer Overflow in vim/vim prior to 8.2.
Heap-based Buffer Overflow in vim/vim prior to 8.2.
nvd
CVE-2025-24230P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24230 [CRITICAL] CWE-125 CVE-2025-24230: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Playing a malicious audio file may lead to an unexpected app termination.
nvd
CVE-2025-24190P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24190 [CRITICAL] CWE-400 CVE-2025-24190: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2019-8527P3CRITICALCVSS 9.1≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8527 [CRITICAL] CWE-120 CVE-2019-8527: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macO
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2025-43234P3CRITICALCVSS 9.8fixed in 15.62025-07-30
CVE-2025-43234 [CRITICAL] CWE-20 CVE-2025-43234: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted texture may lead to unexpected app termination.
nvd