cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1477MEDIUM1550LOW152

Vulnerabilities

Page 28 of 172
CVE-2021-30856P3CRITICALCVSS 9.1≥ 11.0, < 11.3≥ unspecified, < 11.32021-08-24
CVE-2021-30856 [CRITICAL] CWE-863 CVE-2021-30856: This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Se This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences.
nvd
CVE-2021-30975P3HIGHCVSS 8.6≥ 11.0, < 11.6.2≥ 12.0, < 12.1+3 more2021-08-24
CVE-2021-30975 [HIGH] CWE-863 CVE-2021-30975: This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. T This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious OSAX scripting addition may bypass Gatekeeper checks and circumvent sandbox restrictions.
nvd
CVE-2020-27911P3HIGHCVSS 7.8≥ 11.0, < 11.0.1≥ unspecified, < 11.0+2 more2020-12-08
CVE-2020-27911 [HIGH] CWE-190 CVE-2020-27911: An integer overflow was addressed through improved input validation. This issue is fixed in macOS Bi An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2024-44270P3HIGHCVSS 8.6fixed in 13.7.1≥ 14.0, < 14.7.1+2 more2024-10-28
CVE-2024-44270 [HIGH] CWE-863 CVE-2024-44270: A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, mac A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2025-43400P3MEDIUMCVSS 6.3≥ 14.0, < 14.8.1≥ 15.0, < 15.7.1+4 more2025-09-29
CVE-2025-43400 [MEDIUM] CWE-787 CVE-2025-43400: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, macOS Sequoia 15.7.1, macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, tvOS 26.1, visionOS 26.0.1, watchOS 26.1. Processing a maliciously crafted font may lead to unexpected app termination or corrupt p
nvd
CVE-2026-28995P3HIGHCVSS 8.8≥ 26.0, < 26.5fixed in 26.52026-05-11
CVE-2026-28995 [HIGH] CWE-269 CVE-2026-28995: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.
nvd
CVE-2025-43524P3HIGHCVSS 8.8≥ 14.0, < 14.8.7≥ 15.0, < 15.7.7+1 more2026-05-12
CVE-2025-43524 [HIGH] CWE-284 CVE-2025-43524: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
nvd
CVE-2022-32892P3HIGHCVSS 8.6fixed in 13.0≥ unspecified, < 13+2 more2022-11-01
CVE-2022-32892 [HIGH] CVE-2022-32892: An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iO An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2025-43257P3HIGHCVSS 8.7fixed in 15.62026-04-02
CVE-2025-43257 [HIGH] CWE-59 CVE-2025-43257: This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.
nvd
CVE-2024-27813P3HIGHCVSS 8.6≥ 14.0, < 14.5fixed in 14.52024-05-14
CVE-2024-27813 [HIGH] CVE-2024-27813: The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may b The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
nvd
CVE-2023-42838P3HIGHCVSS 8.6≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-02-21
CVE-2023-42838 [HIGH] CWE-284 CVE-2023-42838: An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
nvd
CVE-2020-25709P3HIGHCVSS 7.5≥ 11.0, < 11.0.12021-05-18
CVE-2020-25709 [HIGH] CWE-617 CVE-2020-25709: A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be pro A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-9876P3HIGHCVSS 7.8≥ 11.0, ≤ 11.0.1≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9876 [HIGH] CWE-787 CVE-2020-9876: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary
nvd
CVE-2024-27857P3HIGHCVSS 7.8≥ 14.0, < 14.5fixed in 14.52024-06-10
CVE-2024-27857 [HIGH] CWE-119 CVE-2024-27857: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
nvd
CVE-2020-27912P3HIGHCVSS 7.8fixed in 11.0.1≥ unspecified, < 11.0+2 more2020-12-08
CVE-2020-27912 [HIGH] CWE-787 CVE-2020-27912: An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Bi An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9889P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.62020-10-16
CVE-2020-9889 [HIGH] CWE-787 CVE-2020-9889: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2026-28821P3HIGHCVSS 8.4≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-28821 [HIGH] CWE-20 CVE-2026-28821: A validation issue existed in the entitlement verification. This issue was addressed with improved v A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain elevated privileges.
nvd
CVE-2022-22579P3HIGHCVSS 7.8fixed in 11.6.3≥ 12.0.0, < 12.2+3 more2022-03-18
CVE-2022-22579 [HIGH] CVE-2022-22579: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2020-9919P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9919 [HIGH] CWE-787 CVE-2020-9919: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30980P3HIGHCVSS 7.8≥ 11.0, < 11.6.2≥ 12.0, < 12.1+4 more2021-08-24
CVE-2021-30980 [HIGH] CWE-416 CVE-2021-30980: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
Apple macOS vulnerabilities | cvebase