Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 47 of 172
CVE-2020-36224P3HIGHCVSS 7.5≥ 11.1, < 11.42021-01-26
CVE-2020-36224 [HIGH] CWE-763 CVE-2020-36224: A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash i
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
nvd
CVE-2020-3883P3HIGHCVSS 8.8≥ unspecified, < macOS Catalina 10.15.42020-04-01
CVE-2020-3883 [HIGH] CVE-2020-3883: This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macO
This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to use arbitrary entitlements.
nvd
CVE-2022-22637P3HIGHCVSS 8.8≥ 12.0, < 12.32022-09-23
CVE-2022-22637 [HIGH] CWE-346 CVE-2022-22637: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
nvd
CVE-2022-26696P3HIGHCVSS 8.8≥ 12.0.0, < 12.4≥ unspecified, < 12.42022-09-20
CVE-2022-26696 [HIGH] CWE-693 CVE-2022-26696: This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monter
This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2019-8852P3HIGHCVSS 7.8≥ unspecified, < 10.152020-10-27
CVE-2019-8852 [HIGH] CWE-787 CVE-2019-8852: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30688P3HIGHCVSS 8.8≥ 11.0, < 11.4≥ unspecified, < 11.4+1 more2021-09-08
CVE-2021-30688 [HIGH] CVE-2021-30688: A malicious application may be able to break out of its sandbox. This issue is fixed in macOS Big Su
A malicious application may be able to break out of its sandbox. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina. A path handling issue was addressed with improved validation.
nvd
CVE-2023-23532P3HIGHCVSS 8.8fixed in 13.3≥ unspecified, < 13.32023-05-08
CVE-2023-23532 [HIGH] CVE-2023-23532: This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 a
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.6 and iPadOS 15.7.6. An app may be able to break out of its sandbox.
nvd
CVE-2022-32890P3HIGHCVSS 8.6fixed in 13.0≥ unspecified, < 132022-11-01
CVE-2022-32890 [HIGH] CVE-2022-32890: A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. A sandbox
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2022-1619P3HIGHCVSS 7.8fixed in 13.02022-05-08
CVE-2022-1619 [HIGH] CWE-122 CVE-2022-1619: Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
nvd
CVE-2020-9967P3HIGHCVSS 7.8≥ 11.0, < 11.1.0≥ unspecified, < 11.0+1 more2021-04-02
CVE-2020-9967 [HIGH] CWE-787 CVE-2020-9967: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memo
nvd
CVE-2023-42947P3HIGHCVSS 8.6≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42947 [HIGH] CWE-22 CVE-2023-42947: A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey
A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.
nvd
CVE-2020-9973P3HIGHCVSS 7.8≥ unspecified, < 10.15≥ unspecified, < 14.02020-10-27
CVE-2020-9973 [HIGH] CWE-125 CVE-2020-9973: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Cata
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2019-8803P3HIGHCVSS 8.4≥ unspecified, < macOS Catalina 10.15.12019-12-18
CVE-2019-8803 [HIGH] CWE-613 CVE-2019-8803: An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..
nvd
CVE-2025-24255P3HIGHCVSS 8.4≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24255 [HIGH] CWE-20 CVE-2025-24255: A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequo
A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.
nvd
CVE-2017-13905P3HIGHCVSS 8.1fixed in 10.13.2≥ unspecified, < 10.13+1 more2021-12-23
CVE-2017-13905 [HIGH] CWE-362 CVE-2017-13905: A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.
A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
nvd
CVE-2019-6210P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6210 [HIGH] CWE-787 CVE-2019-6210: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-31234P3HIGHCVSS 8.2fixed in 15.52025-05-12
CVE-2025-31234 [HIGH] CWE-119 CVE-2025-31234: The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS
The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2022-22593P3HIGHCVSS 7.8≥ 11.0, < 11.6.3≥ 12.0.0, < 12.2+3 more2022-03-18
CVE-2022-22593 [HIGH] CWE-120 CVE-2022-22593: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-9892P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9892 [HIGH] CWE-787 CVE-2020-9892: Multiple memory corruption issues were addressed with improved state management. This issue is fixed
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-3919P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.42020-04-01
CVE-2020-3919 [HIGH] CWE-665 CVE-2020-3919: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd