Apple macOS vulnerabilities

3,135 known vulnerabilities affecting apple/macos.

Total CVEs
3,135
CISA KEV
75
actively exploited
Public exploits
44
Exploited in wild
61
Severity breakdown
CRITICAL203HIGH1362MEDIUM1421LOW149

Vulnerabilities

Page 59 of 157
CVE-2024-27834MEDIUMCVSS 5.5≥ 14.0, < 14.5fixed in 14.52024-05-14
CVE-2024-27834 [MEDIUM] CWE-277 CVE-2024-27834: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPa The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2024-27789MEDIUMCVSS 5.5≥ 12.0, < 12.7.5≥ 13.0, < 13.6.7+4 more2024-05-14
CVE-2024-27789 [MEDIUM] CWE-922 CVE-2024-27789: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7. A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.7. An app may be able to access user-sensitive data.
nvd
CVE-2024-27837LOWCVSS 3.3≥ 14.0, < 14.5fixed in 14.52024-05-14
CVE-2024-27837 [LOW] CWE-280 CVE-2024-27837: A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in ma A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.
nvd
CVE-2024-4558CRITICALCVSS 9.6fixed in 14.62024-05-07
CVE-2024-4558 [CRITICAL] CWE-416 CVE-2024-4558: Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potent Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-27791HIGHCVSS 7.1≥ 12.0, < 12.7.3≥ 13.0, < 13.6.4+4 more2024-04-24
CVE-2024-27791 [HIGH] CWE-119 CVE-2024-27791: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, i The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3. An app may be able to corrupt coprocessor memory.
nvd
CVE-2024-23271MEDIUMCVSS 6.5≥ 14.0, < 14.3fixed in 14.32024-04-24
CVE-2024-23271 [MEDIUM] CWE-284 CVE-2024-23271: A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and i A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
nvd
CVE-2023-38709HIGHCVSS 7.3fixed in 14.62024-04-04
CVE-2023-38709 [HIGH] CWE-1284 CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content genera Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
nvd
CVE-2024-24795MEDIUMCVSS 6.3fixed in 14.62024-04-04
CVE-2024-24795 [MEDIUM] CWE-113 CVE-2024-24795: HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.
nvd
CVE-2023-42974HIGHCVSS 7.0≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42974 [HIGH] CWE-362 CVE-2023-42974: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1 A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-42950HIGHCVSS 8.8≥ 14.0, < 14.2≥ unspecified, < 14.22024-03-28
CVE-2023-42950 [HIGH] CWE-416 CVE-2023-42950: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2023-42892HIGHCVSS 7.8≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42892 [HIGH] CWE-416 CVE-2023-42892: A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS V A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A local attacker may be able to elevate their privileges.
nvd
CVE-2023-42913HIGHCVSS 8.8fixed in 14.2≥ unspecified, < 14.22024-03-28
CVE-2023-42913 [HIGH] CWE-922 CVE-2023-42913: This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2 This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions.
nvd
CVE-2023-42947HIGHCVSS 8.6≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42947 [HIGH] CWE-22 CVE-2023-42947: A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.
nvd
CVE-2023-42931HIGHCVSS 7.8≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42931 [HIGH] CWE-280 CVE-2023-42931: The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Son The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.
nvd
CVE-2023-42893MEDIUMCVSS 5.5≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42893 [MEDIUM] CVE-2023-42893: A permissions issue was addressed by removing vulnerable code and adding additional checks. This iss A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access protected user data.
nvd
CVE-2023-40390MEDIUMCVSS 5.5fixed in 14.2≥ unspecified, < 14.22024-03-28
CVE-2023-40390 [MEDIUM] CVE-2023-40390: A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be able to access user-sensitive data.
nvd
CVE-2023-42896MEDIUMCVSS 5.5≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42896 [MEDIUM] CWE-862 CVE-2023-42896: An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monte An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected parts of the file system.
nvd
CVE-2023-42956MEDIUMCVSS 6.5≥ 14.0, < 14.2≥ unspecified, < 14.22024-03-28
CVE-2023-42956 [MEDIUM] CVE-2023-42956: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.
nvd
CVE-2023-42930MEDIUMCVSS 5.5≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42930 [MEDIUM] CVE-2023-42930: This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS So This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be able to modify protected parts of the file system.
nvd
CVE-2023-42936MEDIUMCVSS 5.5≥ 12.0, < 12.7.2≥ 13.0, < 13.6.3+4 more2024-03-28
CVE-2023-42936 [MEDIUM] CWE-200 CVE-2023-42936: This issue was addressed with improved redaction of sensitive information. This issue is fixed in ma This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access user-sensitive data.
nvd
Apple macOS vulnerabilities | cvebase