cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1477MEDIUM1550LOW152

Vulnerabilities

Page 41 of 172
CVE-2020-27931P3HIGHCVSS 7.8≥ unspecified, < 11.0≥ unspecified, < 11.12021-04-02
CVE-2020-27931 [HIGH] CWE-787 CVE-2020-27931: A memory corruption issue existed in the processing of font files. This issue was addressed with imp A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0. Processing a maliciously crafted font file may
nvd
CVE-2022-26756P3HIGHCVSS 7.8≥ 11.0, < 11.6.6≥ 12.0, < 12.4+2 more2022-05-26
CVE-2022-26756 [HIGH] CWE-787 CVE-2022-26756: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Se An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-64713P3HIGHCVSS 8.1fixed in 26.62026-07-27
CVE-2026-64713 [HIGH] CWE-203 CVE-2026-64713: This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPad This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.
nvd
CVE-2022-42916P3HIGHCVSS 7.5fixed in 12.6.3≥ 13.0, < 13.22022-10-29
CVE-2022-42916 [HIGH] CWE-319 CVE-2022-42916: In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using it In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replac
nvd
CVE-2022-22585P3HIGHCVSS 7.5fixed in 11.6.3≥ 12.0.0, < 12.2+2 more2022-03-18
CVE-2022-22585 [HIGH] CWE-59 CVE-2022-22585: An issue existed within the path validation logic for symlinks. This issue was addressed with improv An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access a user's files.
nvd
CVE-2024-27818P3HIGHCVSS 7.8≥ 14.0, < 14.5fixed in 14.52024-05-14
CVE-2024-27818 [HIGH] CWE-77 CVE-2024-27818: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.
nvd
CVE-2024-23265P3HIGHCVSS 7.8≥ 12.0, < 12.7.4≥ 13.0, < 13.6.5+4 more2024-03-08
CVE-2024-23265 [HIGH] CWE-787 CVE-2024-23265: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2019-8561P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8561 [HIGH] CWE-20 CVE-2019-8561: A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to elevate privileges.
nvd
CVE-2022-32924P3HIGHCVSS 7.8fixed in 13.0≥ 11.0, < 11.7+2 more2022-11-01
CVE-2022-32924 [HIGH] CWE-94 CVE-2022-32924: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big S The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-38572P3HIGHCVSS 7.5≥ 13.0, < 13.5≥ unspecified, < 13.52023-07-27
CVE-2023-38572 [HIGH] CVE-2023-38572: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, i The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. A website may be able to bypass Same Origin Policy.
nvd
CVE-2025-24224P3HIGHCVSS 7.5fixed in 13.7.7≥ 15.0, < 15.5+1 more2025-07-30
CVE-2025-24224 [HIGH] CWE-754 CVE-2025-24224: The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequoia 15.5, macOS Ventura 13.7.7, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to cause unexpected system termination.
nvd
CVE-2022-32897P3HIGHCVSS 7.8fixed in 12.5≥ unspecified, < 12.52024-06-10
CVE-2022-32897 [HIGH] CWE-787 CVE-2022-32897: A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monte A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff file may lead to arbitrary code execution.
nvd
CVE-2024-23247P3HIGHCVSS 7.8≥ 12.0, < 12.7.4≥ 13.0, < 13.6.5+4 more2024-03-08
CVE-2024-23247 [HIGH] CWE-77 CVE-2024-23247: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
nvd
CVE-2023-41063P3HIGHCVSS 7.8≥ 13.0, < 13.6≥ unspecified, < 13.6+1 more2023-09-27
CVE-2023-41063 [HIGH] CVE-2023-41063: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-42841P3HIGHCVSS 7.8≥ 13.0, < 13.6.1≥ 14.0, < 14.1+2 more2023-10-25
CVE-2023-42841 [HIGH] CWE-119 CVE-2023-42841: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2024-23212P3HIGHCVSS 7.8≥ 12.0, < 12.7.3≥ 13.0, < 13.6.4+4 more2024-01-23
CVE-2024-23212 [HIGH] CVE-2024-23212: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-43668P3HIGHCVSS 7.5≥ 14.0, < 14.8.7≥ 15.0, < 15.7.7+4 more2026-05-11
CVE-2026-43668 [HIGH] CWE-416 CVE-2026-43668: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2021-30704P3HIGHCVSS 7.8≥ 11.0, < 11.4≥ unspecified, < 11.4+3 more2021-09-08
CVE-2021-30704 [HIGH] CVE-2021-30704: A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Securi A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-41071P3HIGHCVSS 7.8≥ 13.0, < 13.6≥ unspecified, < 13.62023-09-27
CVE-2023-41071 [HIGH] CWE-416 CVE-2023-41071: A use-after-free issue was addressed with improved memory management. This issue is fixed in tvOS 17 A use-after-free issue was addressed with improved memory management. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Ventura 13.6. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-40412P3HIGHCVSS 7.8≥ 12.0.0, < 12.7≥ 13.0, < 13.6+2 more2023-09-27
CVE-2023-40412 [HIGH] CVE-2023-40412: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.
nvd
Apple macOS vulnerabilities | cvebase