Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL204HIGH1438MEDIUM1494LOW151UNKNOWN151
Vulnerabilities
Page 4 of 172
CVE-2024-23296P1HIGHCVSS 7.8KEV≥ 12.0, < 12.7.6≥ 13.0, < 13.6.7+4 more2024-03-05
CVE-2024-23296 [HIGH] CWE-787 CVE-2024-23296: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protection
nvd
CVE-2021-30713P1HIGHCVSS 7.8KEVfixed in 11.4≥ unspecified, < 11.42021-09-08
CVE-2021-30713 [HIGH] CWE-862 CVE-2021-30713: A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2024-44309P1MEDIUMCVSS 6.3KEV≥ 15.0, < 15.1.1fixed in 15.1.12024-11-20
CVE-2024-44309 [MEDIUM] CWE-79 CVE-2024-44309: A cookie management issue was addressed with improved state management. This issue is fixed in Safar
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been a
nvd
CVE-2021-30869P1HIGHCVSS 7.8KEV≥ 11.0, < 11.2≥ unspecified, < 11.2+2 more2021-08-24
CVE-2021-30869 [HIGH] CWE-843 CVE-2021-30869: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware o
nvd
CVE-2023-42916P1MEDIUMCVSS 6.5KEV≥ 14.0, < 14.1.2≥ unspecified, < 14.12023-11-30
CVE-2023-42916 [MEDIUM] CWE-125 CVE-2023-42916: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd
CVE-2020-9859P1HIGHCVSS 7.8KEV≥ unspecified, < macOS Catalina 10.15.5 Supplemental Update2020-06-05
CVE-2020-9859 [HIGH] CWE-415 CVE-2020-9859: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 1
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-28204P1MEDIUMCVSS 6.5KEV≥ 13.0, < 13.4≥ unspecified, < 13.42023-06-23
CVE-2023-28204 [MEDIUM] CWE-125 CVE-2023-28204: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
nvd
CVE-2023-38606P1MEDIUMCVSS 5.5KEV≥ 11.0, < 11.7.9≥ 12.0.0, < 12.6.8+4 more2023-07-27
CVE-2023-38606 [MEDIUM] CVE-2023-38606: This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.
This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited again
nvd
CVE-2019-8526P1HIGHCVSS 7.8KEV≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8526 [HIGH] CWE-416 CVE-2019-8526: A use after free issue was addressed with improved memory management. This issue is fixed in macOS M
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
nvd
CVE-2025-43510P1HIGHCVSS 7.8KEV≥ 14.0, < 14.8.2≥ 15.0, < 15.7.2+4 more2025-12-12
CVE-2025-43510 [HIGH] CWE-667 CVE-2025-43510: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
nvd
CVE-2021-31010P2HIGHCVSS 7.5KEV≥ 11.0, < 11.6≥ unspecified, < 11.6+1 more2021-08-24
CVE-2021-31010 [HIGH] CWE-502 CVE-2021-31010: A deserialization issue was addressed through improved validation. This issue is fixed in Security U
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the tim
nvd
CVE-2025-43520P1MEDIUMCVSS 5.5KEV≥ 14.0, < 14.8.2≥ 15.0, < 15.7.2+4 more2025-12-12
CVE-2025-43520 [MEDIUM] CWE-120 CVE-2025-43520: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2025-43200P2MEDIUMCVSS 4.2KEV≥ 13.0, < 13.7.4≥ 14.0, < 14.7.4+4 more2025-06-16
CVE-2025-43200 [MEDIUM] CVE-2025-43200: This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4,
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via
nvd
CVE-2019-6223P2HIGHCVSS 7.5KEV≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6223 [HIGH] CVE-2019-6223: A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.
nvd
CVE-2022-22674P2MEDIUMCVSS 5.5KEV≥ 11.0, < 11.6.6≥ 12.0.0, < 12.3.1+3 more2022-05-26
CVE-2022-22674 [MEDIUM] CWE-125 CVE-2022-22674: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.
nvd
CVE-2024-6387P1HIGHCVSS 8.1ExploitedPoC≥ 12.0, < 12.7.6≥ 13.0, < 13.6.8+1 more2024-07-01
CVE-2024-6387 [HIGH] CWE-364 CVE-2024-6387: A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race con
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
nvd
CVE-2023-48795P1MEDIUMCVSS 5.9ExploitedPoC≥ 14.0, < 14.42023-12-18
CVE-2023-48795 [MEDIUM] CWE-354 CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgr
nvd
CVE-2023-22809P1HIGHCVSS 7.8ExploitedPoCfixed in 13.42023-01-18
CVE-2023-22809 [HIGH] CWE-269 CVE-2023-22809: In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem e
nvd
CVE-2022-46689P1HIGHCVSS 7.0ExploitedPoCfixed in 11.7.2≥ 12.0, < 12.6.2+2 more2022-12-15
CVE-2022-46689 [HIGH] CWE-362 CVE-2022-46689: A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS M
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8646P1HIGHCVSS 7.5ExploitedPoCRansomware≥ unspecified, < macOS Mojave 10.14.62019-12-18
CVE-2019-8646 [HIGH] CWE-125 CVE-2019-8646: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to leak memory.
nvd