Apple macOS vulnerabilities
3,180 known vulnerabilities affecting apple/macos.
Total CVEs
3,180
CISA KEV
75
actively exploited
Public exploits
44
Exploited in wild
61
Severity breakdown
CRITICAL211HIGH1380MEDIUM1439LOW150
Vulnerabilities
Page 24 of 159
CVE-2025-43213MEDIUMCVSS 6.5fixed in 15.62025-07-30
CVE-2025-43213 [MEDIUM] CWE-119 CVE-2025-43213: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43260MEDIUMCVSS 5.1fixed in 14.7.7≥ 15.0, < 15.6+1 more2025-07-30
CVE-2025-43260 [MEDIUM] CWE-266 CVE-2025-43260: This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, m
This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.
cvelistv5nvd
CVE-2025-43214MEDIUMCVSS 6.5fixed in 15.62025-07-30
CVE-2025-43214 [MEDIUM] CWE-119 CVE-2025-43214: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43276MEDIUMCVSS 5.3fixed in 15.62025-07-30
CVE-2025-43276 [MEDIUM] CWE-367 CVE-2025-43276: A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6.
A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at the same time.
cvelistv5nvd
CVE-2025-43251MEDIUMCVSS 5.5fixed in 15.62025-07-30
CVE-2025-43251 [MEDIUM] CWE-863 CVE-2025-43251: An authorization issue was addressed with improved state management. This issue is fixed in macOS Se
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.6. A local attacker may gain access to Keychain items.
cvelistv5nvd
CVE-2025-31275MEDIUMCVSS 6.2fixed in 15.62025-07-30
CVE-2025-31275 [MEDIUM] CWE-274 CVE-2025-31275: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to launch any installed app.
cvelistv5nvd
CVE-2025-43191MEDIUMCVSS 6.2fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43191 [MEDIUM] CWE-22 CVE-2025-43191: A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 1
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.
cvelistv5nvd
CVE-2025-43197MEDIUMCVSS 4.0fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43197 [MEDIUM] CWE-863 CVE-2025-43197: This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.
cvelistv5nvd
CVE-2025-43241MEDIUMCVSS 5.5fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43241 [MEDIUM] CWE-284 CVE-2025-43241: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to read files outside of its sandbox.
cvelistv5nvd
CVE-2025-43226MEDIUMCVSS 4.0fixed in 14.7.7≥ 15.0, < 15.6+1 more2025-07-30
CVE-2025-43226 [MEDIUM] CWE-125 CVE-2025-43226: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted image may result in disclosure of process memory.
cvelistv5nvd
CVE-2025-43225MEDIUMCVSS 5.5fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43225 [MEDIUM] CWE-532 CVE-2025-43225: A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, ma
A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.
cvelistv5nvd
CVE-2025-43206MEDIUMCVSS 4.0fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43206 [MEDIUM] CWE-22 CVE-2025-43206: A parsing issue in the handling of directory paths was addressed with improved path validation. This
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected user data.
cvelistv5nvd
CVE-2025-43185MEDIUMCVSS 5.5fixed in 15.62025-07-30
CVE-2025-43185 [MEDIUM] CWE-347 CVE-2025-43185: A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in ma
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to access protected user data.
cvelistv5nvd
CVE-2025-43215MEDIUMCVSS 5.5fixed in 15.62025-07-30
CVE-2025-43215 [MEDIUM] CWE-200 CVE-2025-43215: The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may result in disclosure of process memory.
cvelistv5nvd
CVE-2025-43267MEDIUMCVSS 5.5fixed in 15.62025-07-30
CVE-2025-43267 [MEDIUM] CWE-74 CVE-2025-43267: An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6. An app may be able to access sensitive user data.
cvelistv5nvd
CVE-2025-43250MEDIUMCVSS 4.0fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43250 [MEDIUM] CWE-22 CVE-2025-43250: A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 1
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.
cvelistv5nvd
CVE-2025-43274MEDIUMCVSS 4.4fixed in 15.62025-07-30
CVE-2025-43274 [MEDIUM] CWE-311 CVE-2025-43274: A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to circumvent sandbox restrictions.
cvelistv5nvd
CVE-2025-43246MEDIUMCVSS 5.5fixed in 14.7.7≥ 15.0, < 15.6+1 more2025-07-30
CVE-2025-43246 [MEDIUM] CWE-200 CVE-2025-43246: This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sono
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access sensitive user data.
cvelistv5nvd
CVE-2025-43216MEDIUMCVSS 6.5fixed in 15.62025-07-30
CVE-2025-43216 [MEDIUM] CWE-416 CVE-2025-43216: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
cvelistv5nvd
CVE-2025-43230MEDIUMCVSS 4.0fixed in 15.62025-07-30
CVE-2025-43230 [MEDIUM] CWE-863 CVE-2025-43230: The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPad
The issue was addressed with additional permissions checks. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. An app may be able to access user-sensitive data.
cvelistv5nvd