cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1477MEDIUM1550LOW152

Vulnerabilities

Page 20 of 172
CVE-2026-43705P3HIGHCVSS 8.8fixed in 26.5.22026-06-29
CVE-2026-43705 [HIGH] CWE-843 CVE-2026-43705: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-28947P3HIGHCVSS 8.8≥ 26.0, < 26.5fixed in 26.52026-05-11
CVE-2026-28947 [HIGH] CWE-416 CVE-2026-28947: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43419P3HIGHCVSS 8.8fixed in 262025-11-04
CVE-2025-43419 [HIGH] CWE-119 CVE-2025-43419: The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-20631P3HIGHCVSS 8.8≥ 26.0, < 26.4fixed in 26.42026-03-25
CVE-2026-20631 [HIGH] CVE-2026-20631: A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user ma A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user may be able to elevate privileges.
nvd
CVE-2020-9918P3CRITICALCVSS 9.8≥ unspecified, < macOS Catalina 10.15.62020-10-16
CVE-2020-9918 [CRITICAL] CWE-125 CVE-2020-9918: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2025-24211P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24211 [CRITICAL] CWE-400 CVE-2025-24211: This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 1 This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2020-9883P3HIGHCVSS 7.8≥ 11.0, < 11.0.1v11.0.1+1 more2020-10-22
CVE-2020-9883 [HIGH] CWE-120 CVE-2020-9883: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-32847P3CRITICALCVSS 9.1fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32847 [CRITICAL] CWE-119 CVE-2022-32847: This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macO This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2025-43209P3CRITICALCVSS 9.8fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43209 [CRITICAL] CWE-787 CVE-2025-43209: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43347P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43347 [CRITICAL] CWE-20 CVE-2025-43347: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 2 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed.
nvd
CVE-2021-39537P3HIGHCVSS 8.8v11.7v13.02021-09-20
CVE-2021-39537 [HIGH] CWE-787 CVE-2021-39537: An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buf An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
nvd
CVE-2013-0340P3MEDIUMCVSS 6.8fixed in 11.62014-01-21
CVE-2013-0340 [MEDIUM] CWE-611 CVE-2013-0340: expat before version 2.4.0 does not properly handle entities expansion unless an application develop expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE
nvd
CVE-2025-43526P3CRITICALCVSS 9.8fixed in 26.22025-12-17
CVE-2025-43526 [CRITICAL] CWE-601 CVE-2025-43526: This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tah This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
nvd
CVE-2020-27906P3HIGHCVSS 8.8fixed in 11.0.1≥ unspecified, < 11.02020-12-08
CVE-2020-27906 [HIGH] CWE-190 CVE-2020-27906: Multiple integer overflows were addressed with improved input validation. This issue is fixed in mac Multiple integer overflows were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
CVE-2019-8745P3HIGHCVSS 8.8≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8745 [HIGH] CWE-119 CVE-2019-8745: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15, tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing a maliciously crafted text file may lead to arbitrary code execution.
nvd
CVE-2019-8585P3HIGHCVSS 8.8≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8585 [HIGH] CWE-125 CVE-2019-8585: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. Processing a maliciously crafted movie file may lead to arbitrary code execution.
nvd
CVE-2024-54542P3CRITICALCVSS 9.1fixed in 15.22025-01-27
CVE-2024-54542 [CRITICAL] CWE-862 CVE-2024-54542: An authentication issue was addressed with improved state management. This issue is fixed in Safari An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, watchOS 11.2. Private Browsing tabs may be accessed without authentication.
nvd
CVE-2020-27920P3HIGHCVSS 8.8≥ unspecified, < 11.0≥ unspecified, < 11.12021-04-02
CVE-2020-27920 [HIGH] CWE-416 CVE-2020-27920: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2019-8826P3HIGHCVSS 8.8≥ unspecified, < 10.152020-10-27
CVE-2019-8826 [HIGH] CWE-787 CVE-2019-8826: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-40448P3HIGHCVSS 8.6fixed in 14.0≥ unspecified, < 142023-09-27
CVE-2023-40448 [HIGH] CVE-2023-40448: The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16. The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.
nvd
Apple macOS vulnerabilities | cvebase