Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1477MEDIUM1550LOW152
Vulnerabilities
Page 31 of 172
CVE-2026-43658P3HIGHCVSS 7.5≥ 26.0, < 26.5fixed in 26.52026-05-11
CVE-2026-43658 [HIGH] CWE-119 CVE-2026-43658: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-28976P3HIGHCVSS 7.5≥ 26.0, < 26.5fixed in 26.52026-05-11
CVE-2026-28976 [HIGH] CWE-200 CVE-2026-28976: An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe
An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.
nvd
CVE-2022-23308P3HIGHCVSS 7.5≥ 11.6.0, < 11.6.6≥ 12.0, < 12.42022-02-26
CVE-2022-23308 [HIGH] CWE-416 CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
nvd
CVE-2025-30466P3CRITICALCVSS 9.8fixed in 15.42025-05-29
CVE-2025-30466 [CRITICAL] CWE-346 CVE-2025-30466: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.
nvd
CVE-2026-43778P3CRITICALCVSS 9.8fixed in 14.8.8fixed in 15.7.8+1 more2026-07-27
CVE-2026-43778 [CRITICAL] CWE-416 CVE-2026-43778: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-64729P3CRITICALCVSS 9.8≥ 26.0, < 26.6fixed in 26.62026-07-27
CVE-2026-64729 [CRITICAL] CWE-416 CVE-2026-64729: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64720P3CRITICALCVSS 9.8≥ 26.0, < 26.6fixed in 26.62026-07-27
CVE-2026-64720 [CRITICAL] CWE-362 CVE-2026-64720: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-43814P3CRITICALCVSS 9.8≥ 26.0, < 26.6fixed in 26.62026-07-27
CVE-2026-43814 [CRITICAL] CWE-416 CVE-2026-43814: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-28928P3CRITICALCVSS 9.8≥ 26.0, < 26.6fixed in 26.62026-07-27
CVE-2026-28928 [CRITICAL] CWE-416 CVE-2026-28928: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-43773P3CRITICALCVSS 9.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-43773 [CRITICAL] CWE-125 CVE-2026-43773: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequ
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43802P3CRITICALCVSS 9.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-43802 [CRITICAL] CWE-787 CVE-2026-43802: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64703P3CRITICALCVSS 9.8≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-64703 [CRITICAL] CWE-416 CVE-2026-64703: A use after free issue was addressed with improved memory management. This issue is fixed in macOS S
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.
nvd
CVE-2026-64727P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64727 [CRITICAL] CWE-843 CVE-2026-64727: A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tah
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2020-9868P3CRITICALCVSS 9.1≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9868 [CRITICAL] CWE-295 CVE-2020-9868: A certificate validation issue existed when processing administrator added certificates. This issue
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an ad
nvd
CVE-2024-44206P3CRITICALCVSS 9.3fixed in 14.62024-10-24
CVE-2024-44206 [CRITICAL] CVE-2024-44206: An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in
An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A user may be able to bypass some web content restrictions.
nvd
CVE-2020-8286P3HIGHCVSS 7.5≥ 11.0, < 11.32020-12-14
CVE-2020-8286 [HIGH] CWE-295 CVE-2020-8286: curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insu
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
nvd
CVE-2021-30712P3HIGHCVSS 7.8≥ 11.0, < 11.4≥ unspecified, < 11.4+1 more2021-09-08
CVE-2021-30712 [HIGH] CVE-2021-30712: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvd
CVE-2019-8634P3HIGHCVSS 8.8≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8634 [HIGH] CWE-287 CVE-2019-8634: An authentication issue was addressed with improved state management. This issue is fixed in macOS M
An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged in to another user’s account.
nvd
CVE-1999-1412P4MEDIUMCVSS 5.0PoCv1.01999-06-03
CVE-1999-1412 [MEDIUM] CVE-1999-1412: A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attack
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
nvd
CVE-2026-20677P3CRITICALCVSS 9.0fixed in 14.8.4≥ 26.0, < 26.3+1 more2026-02-11
CVE-2026-20677 [CRITICAL] CWE-362 CVE-2026-20677: A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.
nvd