cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 61 of 172
CVE-2021-30966P3HIGHCVSS 7.5fixed in 12.1≥ unspecified, < 12.1+1 more2021-08-24
CVE-2021-30966 [HIGH] CVE-2021-30966: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. User traffic might unexpectedly be leaked to a proxy server despite PAC configurations.
nvd
CVE-2023-42844P3HIGHCVSS 7.5≥ 12.0.0, < 12.7.1≥ 13.0, < 13.6.1+4 more2023-10-25
CVE-2023-42844 [HIGH] CWE-59 CVE-2023-42844: This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14. This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A website may be able to access sensitive user data when resolving symlinks.
nvd
CVE-2024-27829P3HIGHCVSS 7.8≥ 14.0, < 14.5fixed in 14.52024-05-14
CVE-2024-27829 [HIGH] CWE-788 CVE-2024-27829: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Pro The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
nvd
CVE-2020-9837P3HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9837 [HIGH] CWE-125 CVE-2020-9837: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. A remote attacker may be able to leak memory.
nvd
CVE-2023-32428P3HIGHCVSS 7.8≥ 13.0, < 13.4≥ unspecified, < 13.42023-09-06
CVE-2023-32428 [HIGH] CVE-2023-32428: This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.4, tvO This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to gain root privileges.
nvd
CVE-2022-32812P3HIGHCVSS 7.8fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-08-24
CVE-2022-32812 [HIGH] CWE-787 CVE-2022-32812: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, m The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-43372P3HIGHCVSS 7.8fixed in 26.0fixed in 14.8.2+1 more2025-09-15
CVE-2025-43372 [HIGH] CWE-20 CVE-2025-43372: The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2019-8788P3HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.15.12019-12-18
CVE-2019-8788 [HIGH] CWE-20 CVE-2019-8788: An issue existed in the parsing of URLs. This issue was addressed with improved input validation. Th An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.
nvd
CVE-2020-10010P3HIGHCVSS 7.8≥ unspecified, < 11.02020-12-08
CVE-2020-10010 [HIGH] CWE-22 CVE-2020-10010: A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 1 A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate their privileges.
nvd
CVE-2023-42902P3HIGHCVSS 7.8≥ 14.0, < 14.2≥ unspecified, < 14.22023-12-12
CVE-2023-42902 [HIGH] CWE-787 CVE-2023-42902: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
nvd
CVE-2020-9828P3HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.15.42020-10-22
CVE-2020-9828 [HIGH] CWE-125 CVE-2020-9828: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to leak sensitive user information.
nvd
CVE-2019-8508P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8508 [HIGH] CWE-120 CVE-2019-8508: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Mojave 1 A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.
nvd
CVE-2019-8635P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8635 [HIGH] CWE-415 CVE-2019-8635: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2022-32899P3HIGHCVSS 7.8fixed in 13.0≥ unspecified, < 13+2 more2022-11-01
CVE-2022-32899 [HIGH] CVE-2022-32899: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15 The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8758P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8758 [HIGH] CWE-787 CVE-2019-8758: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with system privileges.
nvd
CVE-2025-24213P3HIGHCVSS 7.8≥ 15.0, < 15.4fixed in 15.52025-03-31
CVE-2025-24213 [HIGH] CWE-843 CVE-2025-24213: This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 1 This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption.
nvd
CVE-2019-8748P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8748 [HIGH] CWE-787 CVE-2019-8748: A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8529P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8529 [HIGH] CWE-787 CVE-2019-8529: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-23539P3HIGHCVSS 7.8≥ 13.0, < 13.2≥ unspecified, < 13.22023-06-23
CVE-2023-23539 [HIGH] CWE-120 CVE-2023-23539: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ve A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.
nvd
CVE-2020-10003P3HIGHCVSS 7.8≥ unspecified, < 11.02020-12-08
CVE-2020-10003 [HIGH] CWE-59 CVE-2020-10003: An issue existed within the path validation logic for symlinks. This issue was addressed with improv An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate their privileges.
nvd
Apple macOS vulnerabilities | cvebase