cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1477MEDIUM1550LOW152

Vulnerabilities

Page 25 of 172
CVE-2026-64696P3CRITICALCVSS 9.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-64696 [CRITICAL] CWE-119 CVE-2026-64696: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43682P3CRITICALCVSS 9.8fixed in 14.8.8fixed in 15.7.8+1 more2026-07-27
CVE-2026-43682 [CRITICAL] CWE-119 CVE-2026-43682: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-64695P3CRITICALCVSS 9.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-64695 [CRITICAL] CWE-119 CVE-2026-64695: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-28982P3CRITICALCVSS 9.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-28982 [CRITICAL] CWE-362 CVE-2026-28982: A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, m A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43807P3CRITICALCVSS 9.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-43807 [CRITICAL] CWE-120 CVE-2026-43807: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.
nvd
CVE-2026-64751P3CRITICALCVSS 9.8≥ 26.0, < 26.6fixed in 26.62026-07-27
CVE-2026-64751 [CRITICAL] CWE-416 CVE-2026-64751: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2026-43748P3CRITICALCVSS 9.8≥ 15.0, < 15.7.8≥ 26.0, < 26.6+2 more2026-07-27
CVE-2026-43748 [CRITICAL] CWE-787 CVE-2026-43748: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2021-30925P3CRITICALCVSS 9.1fixed in 11.6≥ unspecified, < 11.6+1 more2021-08-24
CVE-2021-30925 [CRITICAL] CWE-863 CVE-2021-30925: The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2025-31281P3CRITICALCVSS 9.1fixed in 15.62025-07-30
CVE-2025-31281 [CRITICAL] CWE-20 CVE-2025-31281: An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18 An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2026-39868P3CRITICALCVSS 9.1fixed in 26.5.2fixed in 14.8.8+1 more2026-06-29
CVE-2026-39868 [CRITICAL] CWE-20 CVE-2026-39868: This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadO This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2022-0729P3HIGHCVSS 8.8fixed in 13.02022-02-23
CVE-2022-0729 [HIGH] CWE-823 CVE-2022-0729: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440. Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
nvd
CVE-2024-54498P3HIGHCVSS 8.8fixed in 13.7.2≥ 14.0, < 14.7.2+3 more2024-12-12
CVE-2024-54498 [HIGH] CVE-2024-54498: A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 1 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to break out of its sandbox.
nvd
CVE-2022-28739P3HIGHCVSS 7.5≥ 11.0, < 11.7.1≥ 12.0, < 12.6.12022-05-09
CVE-2022-28739 [HIGH] CWE-125 CVE-2022-28739: There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x b There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.
nvd
CVE-2019-6200P3HIGHCVSS 8.8≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6200 [HIGH] CWE-125 CVE-2019-6200: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.
nvd
CVE-2025-31246P3HIGHCVSS 8.8fixed in 14.7.6≥ 15.0, < 15.5+1 more2025-05-12
CVE-2025-31246 [HIGH] CWE-119 CVE-2025-31246: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, ma The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.
nvd
CVE-2022-26757P3HIGHCVSS 7.8≥ 11.0, < 11.6.6≥ 12.0, < 12.42022-05-26
CVE-2022-26757 [HIGH] CWE-416 CVE-2022-26757: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8604P3HIGHCVSS 8.8≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8604 [HIGH] CWE-787 CVE-2019-8604: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2021-30847P3HIGHCVSS 7.8≥ 11.0, < 11.6≥ unspecified, < 11.6+4 more2021-10-19
CVE-2021-30847 [HIGH] CVE-2021-30847: This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2025-43358P3HIGHCVSS 8.8≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-09-15
CVE-2025-43358 [HIGH] CWE-862 CVE-2025-43358: A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 1 A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A shortcut may be able to bypass sandbox restrictions.
nvd
CVE-2025-43270P3HIGHCVSS 8.8fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43270 [HIGH] CWE-284 CVE-2025-43270: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may gain unauthorized access to Local Network.
nvd
Apple macOS vulnerabilities | cvebase