Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1477MEDIUM1550LOW152
Vulnerabilities
Page 24 of 172
CVE-2021-36690P3HIGHCVSS 7.5fixed in 13.02021-08-24
CVE-2021-36690 [HIGH] CVE-2021-36690: A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the id
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem
nvd
CVE-2024-54525P3HIGHCVSS 8.8fixed in 15.22025-03-17
CVE-2024-54525 [HIGH] CWE-434 CVE-2024-54525: A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS
A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2023-42913P3HIGHCVSS 8.8fixed in 14.2≥ unspecified, < 14.22024-03-28
CVE-2023-42913 [HIGH] CWE-922 CVE-2023-42913: This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2
This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions.
nvd
CVE-2021-30835P3HIGHCVSS 7.8fixed in 11.62021-10-19
CVE-2021-30835 [HIGH] CVE-2021-30835: This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catal
This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-22639P3HIGHCVSS 7.8fixed in 12.3≥ unspecified, < 12.32022-03-18
CVE-2022-22639 [HIGH] CVE-2022-22639: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.
nvd
CVE-2024-27815P3HIGHCVSS 7.8≥ 14.0, < 14.5fixed in 14.52024-06-10
CVE-2024-27815 [HIGH] CWE-787 CVE-2024-27815: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30919P3HIGHCVSS 7.8≥ 11.0, < 11.6.1v12.0+5 more2021-08-24
CVE-2021-30919 [HIGH] CWE-787 CVE-2021-30919: An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.1
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.
nvd
CVE-2021-1882P3CRITICALCVSS 9.8≥ 11.0, < 11.3≥ unspecified, < 11.3+1 more2021-09-08
CVE-2021-1882 [CRITICAL] CWE-787 CVE-2021-1882: A memory corruption issue was addressed with improved validation. This issue is fixed in Security Up
A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to gain elevated privileges.
nvd
CVE-2019-7288P3CRITICALCVSS 9.8≥ unspecified, < 10.142020-10-27
CVE-2019-7288 [CRITICAL] CVE-2019-7288: The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macO
The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service uncovered an issue with Live Photos .
nvd
CVE-2024-44146P3CRITICALCVSS 10.0fixed in 15.0fixed in 152024-09-17
CVE-2024-44146 [CRITICAL] CVE-2024-44146: A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.
nvd
CVE-2025-43187P3HIGHCVSS 7.8≥ 13.0, < 13.7.7≥ 14.0, < 14.7.7+4 more2025-08-29
CVE-2025-43187 [HIGH] CVE-2025-43187: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6,
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Running an hdiutil command may unexpectedly execute arbitrary code.
nvd
CVE-2025-30433P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-30433 [CRITICAL] CWE-284 CVE-2025-30433: This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPad
This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.
nvd
CVE-2024-44148P3CRITICALCVSS 10.0fixed in 15.0fixed in 152024-09-17
CVE-2024-44148 [CRITICAL] CVE-2024-44148: This issue was addressed with improved validation of file attributes. This issue is fixed in macOS S
This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.
nvd
CVE-2026-64764P3HIGHCVSS 7.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-64764 [HIGH] CWE-787 CVE-2026-64764: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
nvd
CVE-2026-20660P3HIGHCVSS 7.5fixed in 14.8.4≥ 26.0, < 26.3+2 more2026-02-11
CVE-2026-20660 [HIGH] CWE-22 CVE-2026-20660: A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.
A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.
nvd
CVE-2025-24195P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24195 [CRITICAL] CWE-276 CVE-2025-24195: An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequo
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.
nvd
CVE-2025-24167P3CRITICALCVSS 9.8fixed in 15.42025-03-31
CVE-2025-24167 [CRITICAL] CVE-2025-24167: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. A download's origin may be incorrectly associated.
nvd
CVE-2025-43253P3CRITICALCVSS 9.8fixed in 14.7.7≥ 15.0, < 15.6+1 more2025-07-30
CVE-2025-43253 [CRITICAL] CWE-20 CVE-2025-43253: This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6,
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to launch arbitrary binaries on a trusted device.
nvd
CVE-2025-43237P3CRITICALCVSS 9.8fixed in 15.62025-07-30
CVE-2025-43237 [CRITICAL] CWE-787 CVE-2025-43237: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-43810P3CRITICALCVSS 9.8fixed in 14.8.8fixed in 15.7.8+1 more2026-07-27
CVE-2026-43810 [CRITICAL] CWE-119 CVE-2026-43810: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd