Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 171 of 172
CVE-2024-23292P4LOWCVSS 3.3≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23292 [LOW] CWE-200 CVE-2024-23292: This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 1
This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access information about a user's contacts.
nvd
CVE-2023-40439P4LOWCVSS 3.3fixed in 13.5≥ unspecified, < 13.52024-01-10
CVE-2023-40439 [LOW] CWE-22 CVE-2023-40439: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to read sensitive location information.
nvd
CVE-2025-24145P4LOWCVSS 3.3fixed in 15.32025-01-27
CVE-2025-24145 [LOW] CWE-532 CVE-2025-24145: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An app may be able to view a contact's phone number in system logs.
nvd
CVE-2024-54491P4LOWCVSS 3.3fixed in 15.22024-12-12
CVE-2024-54491 [LOW] CVE-2024-54491: The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be able to determine a user's current location.
nvd
CVE-2024-23232P4LOWCVSS 3.3≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23232 [LOW] CWE-922 CVE-2024-23232: A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macO
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4. An app may be able to capture a user's screen.
nvd
CVE-2024-23242P4LOWCVSS 3.3≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23242 [LOW] CWE-532 CVE-2024-23242: A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.
A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.
nvd
CVE-2024-23238P4LOWCVSS 3.3≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23238 [LOW] CWE-284 CVE-2024-23238: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to edit NVRAM variables.
nvd
CVE-2024-44298P4LOWCVSS 3.3v15.0fixed in 15.12024-12-20
CVE-2024-44298 [LOW] CWE-922 CVE-2024-44298: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.
nvd
CVE-2023-38605P4LOWCVSS 3.3fixed in 12.6.8≥ 13.0, < 13.5+1 more2023-09-06
CVE-2023-38605 [LOW] CVE-2023-38605: This issue was addressed with improved redaction of sensitive information. This issue is fixed in ma
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.5. An app may be able to determine a user’s current location.
nvd
CVE-2023-40392P4LOWCVSS 3.3fixed in 11.7.9≥ 12.0, < 12.6.8+3 more2023-09-06
CVE-2023-40392 [LOW] CWE-532 CVE-2023-40392: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.5. An app may be able to read sensitive location information.
nvd
CVE-2024-44200P4LOWCVSS 3.3fixed in 15.12024-12-12
CVE-2024-44200 [LOW] CWE-922 CVE-2024-44200: This issue was addressed with improved redaction of sensitive information. This issue is fixed in iO
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to read sensitive location information.
nvd
CVE-2023-42830P4LOWCVSS 3.3fixed in 13.3≥ unspecified, < 13.32024-01-10
CVE-2023-42830 [LOW] CWE-359 CVE-2023-42830: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.
nvd
CVE-2023-28195P4LOWCVSS 3.3≥ 13.0, < 13.3≥ unspecified, < 13.32023-09-06
CVE-2023-28195 [LOW] CVE-2023-28195: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3. An app may be able to read sensitive location information.
nvd
CVE-2024-54558P4LOWCVSS 2.8fixed in 15.0fixed in 152025-03-10
CVE-2024-54558 [LOW] CWE-451 CVE-2024-54558: A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed i
A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.
nvd
CVE-2024-23255P4LOWCVSS 2.4≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23255 [LOW] CWE-287 CVE-2024-23255: An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.
nvd
CVE-2024-44265P4LOWCVSS 2.4fixed in 13.7.1≥ 14.0, < 14.7.1+2 more2024-10-28
CVE-2024-44265 [LOW] CWE-862 CVE-2024-44265: The issue was addressed by restricting options offered on a locked device. This issue is fixed in ma
The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker with physical access can input Game Controller events to apps running on a locked device.
nvd
CVE-2026-64745P4LOWCVSS 2.4≥ 15.0, < 15.7.8≥ 26.0, < 26.6+2 more2026-07-27
CVE-2026-64745 [LOW] CWE-287 CVE-2026-64745: This issue was addressed with additional restrictions on the lock screen. This issue is fixed in mac
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.
nvd
CVE-2024-44123P4LOWCVSS 2.3fixed in 15.0fixed in 152024-10-28
CVE-2024-44123 [LOW] CVE-2024-44123: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iP
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with root privileges may be able to access keyboard input and location information without user consent.
nvd
CVE-2019-8757P4LOWCVSS 2.5≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8757 [LOW] CWE-362 CVE-2019-8757: A race condition existed when reading and writing user preferences. This was addressed with improved
A race condition existed when reading and writing user preferences. This was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15. The "Share Mac Analytics" setting may not be disabled when a user deselects the switch to share analytics.
nvd
CVE-2024-40822P4LOWCVSS 2.4fixed in 14.62024-07-29
CVE-2024-40822 [LOW] CWE-284 CVE-2024-40822: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen.
nvd