cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1477MEDIUM1550LOW152

Vulnerabilities

Page 23 of 172
CVE-2022-26763P3HIGHCVSS 7.8≥ 11.0, < 11.6.6≥ 12.0, < 12.42022-05-26
CVE-2022-26763 [HIGH] CWE-119 CVE-2022-26763: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tv An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious application may be able to execute arbitrary code with system privileges.
nvd
CVE-2023-42910P3HIGHCVSS 8.8≥ 14.0, < 14.2≥ unspecified, < 14.22023-12-12
CVE-2023-42910 [HIGH] CWE-787 CVE-2023-42910: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
nvd
CVE-2022-42828P3HIGHCVSS 8.8≤ 9.0≥ 11.0, < 13.0+1 more2023-08-14
CVE-2022-42828 [HIGH] CVE-2022-42828: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An a The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30721P3MEDIUMCVSS 6.5≥ 11.0.1, < 11.4≥ unspecified, < 11.4+1 more2021-09-08
CVE-2021-30721 [MEDIUM] CVE-2021-30721: A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 1 A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2026-20616P3HIGHCVSS 8.8≥ 14.0, < 14.8.4≥ 26.0, < 26.3+2 more2026-02-11
CVE-2026-20616 [HIGH] CWE-787 CVE-2026-20616: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.
nvd
CVE-2025-43219P3HIGHCVSS 8.8fixed in 15.62026-04-02
CVE-2025-43219 [HIGH] CWE-787 CVE-2025-43219: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Pr The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.
nvd
CVE-2021-30849P3HIGHCVSS 7.8fixed in 12.0.12021-10-19
CVE-2021-30849 [HIGH] CWE-787 CVE-2021-30849: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-27953P3CRITICALCVSS 9.8≥ 11.0, < 11.7.5≥ 12.0, < 12.6.4+4 more2023-05-08
CVE-2023-27953 [CRITICAL] CWE-787 CVE-2023-27953: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, ma The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2019-8749P3CRITICALCVSS 9.8≥ unspecified, < 10.15≥ unspecified, < 12.10+2 more2020-10-27
CVE-2019-8749 [CRITICAL] CWE-787 CVE-2019-8749: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.
nvd
CVE-2019-8756P3CRITICALCVSS 9.8≥ unspecified, < 10.15≥ unspecified, < 12.10+2 more2020-10-27
CVE-2019-8756 [CRITICAL] CWE-787 CVE-2019-8756: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.
nvd
CVE-2022-22641P3CRITICALCVSS 9.8≥ 12.0, < 12.3≥ unspecified, < 12.32022-03-18
CVE-2022-22641 [CRITICAL] CWE-416 CVE-2022-22641: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.
nvd
CVE-2025-30426P3CRITICALCVSS 9.8≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-30426 [CRITICAL] CWE-200 CVE-2025-30426: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2025-31194P3CRITICALCVSS 9.8fixed in 13.7.5≥ 14.0, < 14.7.5+3 more2025-03-31
CVE-2025-31194 [CRITICAL] CWE-862 CVE-2025-31194: An authentication issue was addressed with improved state management. This issue is fixed in macOS S An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A Shortcut may run with admin privileges without authentication.
nvd
CVE-2025-43359P3CRITICALCVSS 9.8≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43359 [CRITICAL] CWE-670 CVE-2025-43359: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A UDP server socket bound to a local interface may become bound to all interfaces.
nvd
CVE-2025-24245P3CRITICALCVSS 9.8fixed in 15.42025-03-31
CVE-2025-24245 [CRITICAL] CWE-862 CVE-2025-24245: This issue was addressed by adding a delay between verification code attempts. This issue is fixed i This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.
nvd
CVE-2020-36230P3HIGHCVSS 7.5≥ 11.1, < 11.42021-01-26
CVE-2020-36230 [HIGH] CWE-617 CVE-2020-36230: A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.50 A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.
nvd
CVE-2023-27958P3CRITICALCVSS 9.1≥ 11.0, < 11.7.5≥ 12.0, < 12.6.4+4 more2023-05-08
CVE-2023-27958 [CRITICAL] CWE-770 CVE-2023-27958: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, ma The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2025-30448P3CRITICALCVSS 9.1fixed in 13.7.6≥ 14.0, < 14.7.6+3 more2025-05-12
CVE-2025-30448 [CRITICAL] CWE-862 CVE-2025-30448: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, visionOS 2.5. An attacker may be able to turn on sharing of an iCloud folder without authentication.
nvd
CVE-2021-30939P3HIGHCVSS 7.8≥ 11.0, < 11.6.2≥ 12.0, < 12.1+4 more2021-08-24
CVE-2021-30939 [HIGH] CWE-125 CVE-2021-30939: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30935P3HIGHCVSS 8.8≥ 11.0, < 11.6.2≥ 12.0, < 12.1+2 more2021-08-24
CVE-2021-30935 [HIGH] CVE-2021-30935: A logic issue was addressed with improved validation. This issue is fixed in Security Update 2021-00 A logic issue was addressed with improved validation. This issue is fixed in Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
Apple macOS vulnerabilities | cvebase