Apple macOS vulnerabilities

3,135 known vulnerabilities affecting apple/macos.

Total CVEs
3,135
CISA KEV
75
actively exploited
Public exploits
44
Exploited in wild
61
Severity breakdown
CRITICAL203HIGH1362MEDIUM1421LOW149

Vulnerabilities

Page 35 of 157
CVE-2025-30425MEDIUMCVSS 4.3≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-30425 [MEDIUM] CWE-284 CVE-2025-30425: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
nvd
CVE-2025-30427MEDIUMCVSS 4.3≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-30427 [MEDIUM] CWE-416 CVE-2025-30427: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-24216MEDIUMCVSS 4.3≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-24216 [MEDIUM] CWE-119 CVE-2025-24216: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-30463MEDIUMCVSS 5.5fixed in 15.42025-03-31
CVE-2025-30463 [MEDIUM] CWE-200 CVE-2025-30463: The issue was addressed with improved restriction of data container access. This issue is fixed in i The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
nvd
CVE-2025-24283MEDIUMCVSS 5.5≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-24283 [MEDIUM] CWE-200 CVE-2025-24283: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPad A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
nvd
CVE-2025-24218MEDIUMCVSS 5.5≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-24218 [MEDIUM] CWE-284 CVE-2025-24218: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. An app may be able to access information about a user's contacts.
nvd
CVE-2025-30438MEDIUMCVSS 5.5≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-30438 [MEDIUM] CWE-284 CVE-2025-30438: This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPad This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started.
nvd
CVE-2025-30435MEDIUMCVSS 5.5≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-30435 [MEDIUM] CWE-200 CVE-2025-30435: This issue was addressed with improved redaction of sensitive information. This issue is fixed in ma This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.
nvd
CVE-2025-24244MEDIUMCVSS 5.5≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24244 [MEDIUM] CWE-200 CVE-2025-24244: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2025-24194MEDIUMCVSS 6.5≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-24194 [MEDIUM] CVE-2025-24194: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, m A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2025-31192MEDIUMCVSS 6.7≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-31192 [MEDIUM] CWE-305 CVE-2025-31192: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.
nvd
CVE-2025-24239MEDIUMCVSS 6.5fixed in 15.42025-03-31
CVE-2025-24239 [MEDIUM] CWE-200 CVE-2025-24239: A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in ma A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
nvd
CVE-2025-24280MEDIUMCVSS 5.5≥ 14.0, < 14.7.5≥ 15.0, < 15.4+2 more2025-03-31
CVE-2025-24280 [MEDIUM] CWE-200 CVE-2025-24280: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.
nvd
CVE-2025-24279MEDIUMCVSS 4.3≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24279 [MEDIUM] CWE-200 CVE-2025-24279: This issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, mac This issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access contacts.
nvd
CVE-2025-30467MEDIUMCVSS 4.3fixed in 15.42025-03-31
CVE-2025-30467 [MEDIUM] CWE-451 CVE-2025-30467: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2025-30454MEDIUMCVSS 5.5≥ 14.0, < 14.7.5≥ 15.0, < 15.4+2 more2025-03-31
CVE-2025-30454 [MEDIUM] CWE-200 CVE-2025-30454: A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iP A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. A malicious app may be able to access private information.
nvd
CVE-2025-24281MEDIUMCVSS 5.5fixed in 15.42025-03-31
CVE-2025-24281 [MEDIUM] CWE-200 CVE-2025-24281: This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. A This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
nvd
CVE-2025-24198MEDIUMCVSS 6.6≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24198 [MEDIUM] CWE-284 CVE-2025-24198: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.
nvd
CVE-2025-24212MEDIUMCVSS 6.3≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24212 [MEDIUM] CVE-2025-24212: This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPad This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvd
CVE-2025-24240MEDIUMCVSS 4.7≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24240 [MEDIUM] CWE-362 CVE-2025-24240: A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4 A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.
nvd