Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 60 of 172
CVE-2020-29618P3HIGHCVSS 7.8≥ 11.0, < 11.1.0≥ unspecified, < 11.1+1 more2021-04-02
CVE-2020-29618 [HIGH] CWE-125 CVE-2020-29618: An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2020-9887P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9887 [HIGH] CWE-787 CVE-2020-9887: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6. Viewing a maliciously crafted JPEG file may lead to arbitrary code execution.
nvd
CVE-2021-1742P3HIGHCVSS 7.8≥ 11.0, < 11.1.0≥ unspecified, < 11.2+2 more2021-04-02
CVE-2021-1742 [HIGH] CVE-2021-1742: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security U
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2019-8829P3HIGHCVSS 7.8≥ unspecified, < 10.15≥ unspecified, < 13.2+1 more2020-10-27
CVE-2019-8829 [HIGH] CWE-667 CVE-2019-8829: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6.1, tvOS 13.2, iOS 13.2 and iPadOS 13.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30907P3HIGHCVSS 7.8≥ 11.0, < 11.6.1v12.0+5 more2021-08-24
CVE-2021-30907 [HIGH] CWE-190 CVE-2021-30907: An integer overflow was addressed through improved input validation. This issue is fixed in iOS 15.1
An integer overflow was addressed through improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to elevate privileges.
nvd
CVE-2021-1880P3HIGHCVSS 7.8≥ 11.0, < 11.3≥ unspecified, < 11.32021-09-08
CVE-2021-1880 [HIGH] CVE-2021-1880: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-22672P3HIGHCVSS 7.8≥ 11.0, < 11.6.5≥ 12.0.0, < 12.3+3 more2022-05-26
CVE-2022-22672 [HIGH] CWE-787 CVE-2022-22672: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.4 and iPadOS 15.4, Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-1768P3HIGHCVSS 7.8≥ 11.0, < 11.2≥ unspecified, < 11.22021-04-02
CVE-2021-1768 [HIGH] CWE-125 CVE-2021-1768: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.
nvd
CVE-2021-1793P3HIGHCVSS 7.8≥ 11.0.1, < 11.2≥ unspecified, < 11.2+2 more2021-04-02
CVE-2021-1793 [HIGH] CVE-2021-1793: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security U
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-1753P3HIGHCVSS 7.8≥ 11.0.1, < 11.2≥ unspecified, < 11.22021-04-02
CVE-2021-1753 [HIGH] CWE-125 CVE-2021-1753: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2018-4302P3HIGHCVSS 7.8≥ unspecified, < 10.132021-12-23
CVE-2018-4302 [HIGH] CWE-476 CVE-2018-4302: A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High
A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.
nvd
CVE-2026-28817P3HIGHCVSS 8.1≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-28817 [HIGH] CWE-362 CVE-2026-28817: A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2026-28891P3HIGHCVSS 8.1≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-28891 [HIGH] CWE-362 CVE-2026-28891: A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
nvd
CVE-2021-1736P3HIGHCVSS 7.8≥ 11.0, < 11.2≥ unspecified, < 11.22021-04-02
CVE-2021-1736 [HIGH] CWE-125 CVE-2021-1736: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-31002P3HIGHCVSS 7.8≥ 11.6, < 11.6.2v12.0.0+2 more2021-08-24
CVE-2021-31002 [HIGH] CWE-125 CVE-2021-31002: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Mon
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.0.1, macOS Big Sur 11.6.2. A malicious application may be able to execute arbitrary code with system privileges.
nvd
CVE-2020-29616P3HIGHCVSS 7.8≥ 11.0, < 11.1.0≥ unspecified, < 11.12021-04-02
CVE-2020-29616 [HIGH] CWE-787 CVE-2020-29616: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-26721P3HIGHCVSS 7.8≥ 11.0, < 11.6.6≥ 12.0, < 12.4+2 more2022-05-26
CVE-2022-26721 [HIGH] CWE-665 CVE-2022-26721: A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalin
A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges.
nvd
CVE-2021-30724P3HIGHCVSS 7.8≥ 11.0.1, < 11.4≥ unspecified, < 11.4+3 more2021-09-08
CVE-2021-30724 [HIGH] CVE-2021-30724: This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 202
This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local attacker may be able to elevate their privileges.
nvd
CVE-2022-26722P3HIGHCVSS 7.8≥ 11.0, < 11.6.6≥ 12.0, < 12.4+2 more2022-05-26
CVE-2022-26722 [HIGH] CWE-665 CVE-2022-26722: A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalin
A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges.
nvd
CVE-2017-13835P3HIGHCVSS 7.8≥ unspecified, < 10.132021-12-23
CVE-2017-13835 [HIGH] CWE-119 CVE-2017-13835: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. An application may be able to execute arbitrary code with elevated privileges.
nvd