cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 172 of 172
CVE-2023-32390P4LOWCVSS 2.4≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32390 [LOW] CWE-125 CVE-2023-32390: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup.
nvd
CVE-2024-27862P4LOWCVSS 2.4≥ 14.0, < 14.6fixed in 14.62024-07-29
CVE-2024-27862 [LOW] CWE-400 CVE-2024-27862: A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6 A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting up a Mac may cause FileVault to become unexpectedly disabled.
nvd
CVE-2022-32879P4LOWCVSS 2.4fixed in 13.0≥ unspecified, < 13+2 more2022-11-01
CVE-2022-32879 [LOW] CVE-2022-32879: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, tvOS 16. A user with physical access to a device may be able to access contacts from the lock screen.
nvd
CVE-2022-32867P4LOWCVSS 2.4fixed in 13.0≥ unspecified, < 13+1 more2022-11-01
CVE-2022-32867 [LOW] CWE-922 CVE-2022-32867: This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.
nvd
CVE-2019-8799P4LOWCVSS 2.4≥ unspecified, < 10.152020-10-27
CVE-2019-8799 [LOW] CVE-2019-8799: This issue was resolved by replacing device names with a random identifier. This issue is fixed in i This issue was resolved by replacing device names with a random identifier. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15, watchOS 6, tvOS 13. An attacker in physical proximity may be able to passively observe device names in AWDL communications.
nvd
CVE-2023-32394P4LOWCVSS 2.4≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-32394 [LOW] CWE-668 CVE-2023-32394: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.
nvd
CVE-2021-30915P4LOWCVSS 2.4≥ 11.0, < 11.6.1v12.0+5 more2021-08-24
CVE-2021-30915 [LOW] CVE-2021-30915: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
nvd
CVE-2023-42874P4LOWCVSS 2.4≥ 14.0, < 14.2≥ unspecified, < 14.22023-12-12
CVE-2023-42874 [LOW] CVE-2023-42874: This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. S This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. Secure text fields may be displayed via the Accessibility Keyboard when using a physical keyboard.
nvd
CVE-2022-22599P4LOWCVSS 2.4fixed in 11.6.5≥ 12.0.0, < 12.3+2 more2022-03-18
CVE-2022-22599 [LOW] CVE-2022-22599: Description: A permissions issue was addressed with improved validation. This issue is fixed in watc Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.
nvd
CVE-2024-54485P4LOWCVSS 2.4fixed in 15.22024-12-12
CVE-2024-54485 [LOW] CWE-922 CVE-2024-54485: The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.
nvd
CVE-2024-44179P4LOWCVSS 2.4fixed in 15.0fixed in 152025-03-10
CVE-2024-44179 [LOW] CWE-200 CVE-2024-44179: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to a device may be able to read contact numbers from the lock screen.
nvd
CVE-2025-43408P4LOWCVSS 2.4fixed in 14.8.2≥ 15.0, < 15.7.2+2 more2025-11-04
CVE-2025-43408 [LOW] CWE-284 CVE-2025-43408: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An attacker with physical access may be able to access contacts from the lock screen.
nvd
CVE-2025-43410P4LOWCVSS 2.4fixed in 14.8.2≥ 15.0, < 15.7.2+2 more2025-12-12
CVE-2025-43410 [LOW] CWE-524 CVE-2025-43410: The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7. The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.2. An attacker with physical access may be able to view deleted notes.
nvd
CVE-2025-43423P4LOWCVSS 2.0fixed in 15.7.2fixed in 26.12025-11-04
CVE-2025-43423 [LOW] CWE-532 CVE-2025-43423: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iP A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlocked device paired with a Mac may be able to view sensitive user information in system logging.
nvd
CVE-2022-32870P4LOWCVSS 2.4fixed in 13.0≥ unspecified, < 13+1 more2022-11-01
CVE-2022-32870 [LOW] CWE-200 CVE-2022-32870: A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ven A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.
nvd
CVE-2021-30918P4LOWCVSS 2.4≥ 12.0.0, < 12.32021-08-24
CVE-2021-30918 [LOW] CVE-2021-30918: A Lock Screen issue was addressed with improved state management. This issue is fixed in iOS 14.8.1 A Lock Screen issue was addressed with improved state management. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.0.1 and iPadOS 15.0.1. A user may be able to view restricted content from the Lock Screen.
nvd
CVE-2019-8777P4LOWCVSS 2.4≥ unspecified, < 10.142020-10-27
CVE-2019-8777 [LOW] CWE-276 CVE-2019-8777: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. A local attacker may be able to view contacts from the lock screen.
nvd
CVE-2021-1755P4LOWCVSS 2.4fixed in 11.0.1≥ unspecified, < 11.02021-04-02
CVE-2021-1755 [LOW] CWE-862 CVE-2021-1755: A lock screen issue allowed access to contacts on a locked device. This issue was addressed with imp A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.
nvd
← Previous172 / 172
Apple macOS vulnerabilities | cvebase