cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 65 of 172
CVE-2025-24233P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24233 [CRITICAL] CWE-863 CVE-2025-24233: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to read or write to protected files.
nvd
CVE-2023-32444P3HIGHCVSS 7.5fixed in 11.7.9≥ 12.0, < 12.6.8+4 more2023-07-28
CVE-2023-32444 [HIGH] CVE-2023-32444: A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.7.9, m A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2026-20620P3HIGHCVSS 7.7≥ 14.0, < 14.8.4≥ 15.0, < 15.7.4+4 more2026-02-11
CVE-2026-20620 [HIGH] CWE-125 CVE-2026-20620: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in mac An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An attacker may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2026-28894P3HIGHCVSS 7.5≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-28894 [HIGH] CWE-20 CVE-2026-28894: A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 2 A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.
nvd
CVE-2025-24253P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24253 [CRITICAL] CWE-200 CVE-2025-24253: This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.
nvd
CVE-2025-43462P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43462 [HIGH] CWE-400 CVE-2025-43462: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2024-44152P3HIGHCVSS 7.5fixed in 15.0fixed in 152024-09-17
CVE-2024-44152 [HIGH] CWE-200 CVE-2024-44152: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive data.
nvd
CVE-2024-44149P3HIGHCVSS 7.5fixed in 15.0fixed in 152024-09-17
CVE-2024-44149 [HIGH] CWE-281 CVE-2024-44149: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.
nvd
CVE-2025-24093P3CRITICALCVSS 9.8fixed in 13.7.3≥ 14.0, < 14.7.3+2 more2025-01-27
CVE-2025-24093 [CRITICAL] CWE-276 CVE-2025-24093: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access removable volumes without user consent.
nvd
CVE-2023-40440P3HIGHCVSS 7.5≥ 12.0.0, < 12.6.8≥ unspecified, < 12.62023-09-12
CVE-2023-40440 [HIGH] CVE-2023-40440: This issue was addressed with improved state management of S/MIME encrypted emails. This issue is fi This issue was addressed with improved state management of S/MIME encrypted emails. This issue is fixed in macOS Monterey 12.6.8. A S/MIME encrypted email may be inadvertently sent unencrypted.
nvd
CVE-2022-32882P3CRITICALCVSS 9.8≥ 11.0, < 11.6.6≥ 12.0.0, < 12.4+2 more2022-09-20
CVE-2022-32882 [CRITICAL] CVE-2022-32882: This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to bypass Privacy preferences.
nvd
CVE-2025-43494P3HIGHCVSS 7.5≥ 14.0, < 14.8.2≥ 15.0, < 15.7.2+4 more2025-12-12
CVE-2025-43494 [HIGH] CWE-20 CVE-2025-43494: A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 an A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An attacker may be able to cause a persistent denial-of-service.
nvd
CVE-2025-43193P3CRITICALCVSS 9.8fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43193 [CRITICAL] CWE-400 CVE-2025-43193: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, ma The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause a denial-of-service.
nvd
CVE-2025-24088P3HIGHCVSS 7.5fixed in 26.0fixed in 262025-09-15
CVE-2025-24088 [HIGH] CWE-284 CVE-2025-24088: The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app ma The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.
nvd
CVE-2026-28987P3HIGHCVSS 7.5≥ 14.0, < 14.8.7≥ 15.0, < 15.7.7+4 more2026-05-11
CVE-2026-28987 [HIGH] CWE-532 CVE-2026-28987: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iP A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state.
nvd
CVE-2025-43184P3CRITICALCVSS 9.8fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43184 [CRITICAL] CWE-284 CVE-2025-43184: This issue was addressed by adding an additional prompt for user consent. This issue is fixed in mac This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A shortcut may be able to bypass sensitive Shortcuts app settings.
nvd
CVE-2025-31247P3HIGHCVSS 7.5fixed in 13.7.6≥ 14.0, < 14.7.6+3 more2025-05-12
CVE-2025-31247 [HIGH] CWE-284 CVE-2025-31247: A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15. A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An attacker may gain access to protected parts of the file system.
nvd
CVE-2026-28974P3HIGHCVSS 7.5≥ 15.0, < 15.7.7≥ 26.0, < 26.5+2 more2026-05-11
CVE-2026-28974 [HIGH] CWE-284 CVE-2026-28974: This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
nvd
CVE-2026-28962P3HIGHCVSS 7.5≥ 26.0, < 26.5fixed in 26.52026-05-11
CVE-2026-28962 [HIGH] CWE-200 CVE-2026-28962: This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2025-31271P3HIGHCVSS 7.5fixed in 26.0fixed in 262025-09-15
CVE-2025-31271 [HIGH] CWE-287 CVE-2025-31271: This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. I This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be accepted on a locked macOS device, even with notifications disabled on the lock screen.
nvd
Apple macOS vulnerabilities | cvebase