Apple macOS vulnerabilities
3,135 known vulnerabilities affecting apple/macos.
Total CVEs
3,135
CISA KEV
75
actively exploited
Public exploits
44
Exploited in wild
61
Severity breakdown
CRITICAL203HIGH1362MEDIUM1421LOW149
Vulnerabilities
Page 54 of 157
CVE-2024-40779MEDIUMCVSS 5.5fixed in 14.62024-07-29
CVE-2024-40779 [MEDIUM] CWE-125 CVE-2024-40779: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2024-40788MEDIUMCVSS 5.5fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-40788 [MEDIUM] CWE-843 CVE-2024-40788: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to cause unexpected system shutdown.
nvd
CVE-2024-40817MEDIUMCVSS 6.1≥ 12.0, < 12.7.6≥ 13.0, < 13.6.8+4 more2024-07-29
CVE-2024-40817 [MEDIUM] CWE-1021 CVE-2024-40817: The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Montere
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2024-40804MEDIUMCVSS 5.5fixed in 14.62024-07-29
CVE-2024-40804 [MEDIUM] CWE-200 CVE-2024-40804: The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious application may be able to access private information.
nvd
CVE-2024-40824MEDIUMCVSS 5.5≥ 14.0, < 14.6fixed in 14.62024-07-29
CVE-2024-40824 [MEDIUM] CWE-281 CVE-2024-40824: This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.
nvd
CVE-2024-27884MEDIUMCVSS 5.5fixed in 14.52024-07-29
CVE-2024-27884 [MEDIUM] CWE-200 CVE-2024-27884: This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, ma
This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to access user-sensitive data.
nvd
CVE-2024-27853MEDIUMCVSS 4.4fixed in 14.42024-07-29
CVE-2024-27853 [MEDIUM] CWE-290 CVE-2024-27853: This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A malicious
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
nvd
CVE-2024-40827MEDIUMCVSS 5.5fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-40827 [MEDIUM] CVE-2024-40827: The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS So
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to overwrite arbitrary files.
nvd
CVE-2024-40806MEDIUMCVSS 5.5fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-40806 [MEDIUM] CWE-125 CVE-2024-40806: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2024-40823MEDIUMCVSS 5.5fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-40823 [MEDIUM] CWE-200 CVE-2024-40823: The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS So
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to access user-sensitive data.
nvd
CVE-2024-40782MEDIUMCVSS 6.5≥ 14.0, < 14.6fixed in 14.62024-07-29
CVE-2024-40782 [MEDIUM] CWE-416 CVE-2024-40782: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2024-27878MEDIUMCVSS 6.7≥ 14.0, < 14.6fixed in 14.62024-07-29
CVE-2024-27878 [MEDIUM] CWE-120 CVE-2024-27878: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS So
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-42943MEDIUMCVSS 5.5fixed in 14.0≥ unspecified, < 142024-07-29
CVE-2023-42943 [MEDIUM] CWE-125 CVE-2023-42943: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14. An app may be able to read sensitive location information.
nvd
CVE-2024-40829MEDIUMCVSS 4.6≥ 13.0, < 13.6.8fixed in 13.6.82024-07-29
CVE-2024-40829 [MEDIUM] CWE-416 CVE-2024-40829: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, i
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker may be able to view restricted content from the lock screen.
nvd
CVE-2024-40800MEDIUMCVSS 5.5≥ 12.0, < 12.7.6≥ 13.0, < 13.6.8+4 more2024-07-29
CVE-2024-40800 [MEDIUM] CWE-281 CVE-2024-40800: An input validation issue was addressed with improved input validation. This issue is fixed in macOS
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
nvd
CVE-2024-27823MEDIUMCVSS 5.9fixed in 12.7.5≥ 13.0, < 13.6.7+3 more2024-07-29
CVE-2024-27823 [MEDIUM] CWE-362 CVE-2024-27823: A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 1
A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network position may be able to spoof network packets.
nvd
CVE-2024-40834MEDIUMCVSS 4.4≤ 12.7.6≥ 13.0, ≤ 13.6.8+4 more2024-07-29
CVE-2024-40834 [MEDIUM] CWE-862 CVE-2024-40834: This issue was addressed by adding an additional prompt for user consent. This issue is fixed in mac
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to bypass sensitive Shortcuts app settings.
nvd
CVE-2024-27863MEDIUMCVSS 5.5fixed in 14.62024-07-29
CVE-2024-27863 [MEDIUM] CVE-2024-27863: An information disclosure issue was addressed with improved private data redaction for log entries.
An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to determine kernel memory layout.
nvd
CVE-2024-27877MEDIUMCVSS 6.1≥ 12.0, < 12.7.6≥ 13, < 13.6.8+4 more2024-07-29
CVE-2024-27877 [MEDIUM] CVE-2024-27877: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.6,
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2024-27883MEDIUMCVSS 4.4fixed in 12.7.6≥ 13.0, < 13.6.8+3 more2024-07-29
CVE-2024-27883 [MEDIUM] CWE-732 CVE-2024-27883: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Montere
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
nvd