cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 77 of 172
CVE-2021-1839P3HIGHCVSS 7.8≥ 11.0, < 11.3≥ unspecified, < 11.3+1 more2021-09-08
CVE-2021-1839 [HIGH] CWE-269 CVE-2021-1839: The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.
nvd
CVE-2024-23276P3HIGHCVSS 7.8≥ 12.0.0, < 12.7.4≥ 13.0, < 13.6.5+4 more2024-03-08
CVE-2024-23276 [HIGH] CWE-269 CVE-2024-23276: A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macO A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
nvd
CVE-2020-9855P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9855 [HIGH] CWE-20 CVE-2020-9855: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.5. A local attacker may be able to elevate their privileges.
nvd
CVE-2023-27938P3HIGHCVSS 7.8fixed in 10.4.8≥ unspecified, < 10.42023-05-08
CVE-2023-27938 [HIGH] CWE-125 CVE-2023-27938: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Gar An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in GarageBand for macOS 10.4.8. Parsing a maliciously crafted MIDI file may lead to an unexpected application termination or arbitrary code execution.
nvd
CVE-2022-46712P3HIGHCVSS 7.8fixed in 13.0≥ unspecified, < 132023-02-27
CVE-2022-46712 [HIGH] CWE-416 CVE-2022-46712: A use after free issue was addressed with improved memory management. This issue is fixed in macOS V A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected system termination or potentially execute code with kernel privileges.
nvd
CVE-2023-32383P3HIGHCVSS 7.8fixed in 11.7.7≥ 12.0.0, < 12.6.6+4 more2024-01-10
CVE-2023-32383 [HIGH] CWE-94 CVE-2023-32383: This issue was addressed by forcing hardened runtime on the affected binaries at the system level. T This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS Ventura 13.4. An app may be able to inject code into sensitive binaries bundled with Xcode.
nvd
CVE-2021-1787P3HIGHCVSS 7.8≥ 11.0, < 11.2≥ unspecified, < 11.2+2 more2021-04-02
CVE-2021-1787 [HIGH] CWE-269 CVE-2021-1787: Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Secur Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges.
nvd
CVE-2022-32826P3HIGHCVSS 7.8fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32826 [HIGH] CWE-269 CVE-2022-32826: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.
nvd
CVE-2025-31184P3HIGHCVSS 7.8≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-31184 [HIGH] CWE-281 CVE-2025-31184: This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.
nvd
CVE-2023-32405P3HIGHCVSS 7.8≥ 11.0, < 11.7.7≥ 12.0, < 12.6.6+4 more2023-06-23
CVE-2023-32405 [HIGH] CWE-276 CVE-2023-32405: A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.7, macOS A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to gain root privileges.
nvd
CVE-2025-30449P3HIGHCVSS 7.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-30449 [HIGH] CWE-281 CVE-2025-30449: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.
nvd
CVE-2023-23497P3HIGHCVSS 7.8≥ 11.0, < 11.7.3≥ 12.0.0, < 12.6.3+4 more2023-02-27
CVE-2023-23497 [HIGH] CWE-269 CVE-2023-23497: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to gain root privileges.
nvd
CVE-2021-1802P3HIGHCVSS 7.8≥ 11.0, < 11.2≥ unspecified, < 11.22021-04-02
CVE-2021-1802 [HIGH] CWE-269 CVE-2021-1802: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A local attacker may be able to elevate their privileges.
nvd
CVE-2023-42828P3HIGHCVSS 7.8fixed in 13.5≥ unspecified, < 13.52024-01-10
CVE-2023-42828 [HIGH] CVE-2023-42828: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.5. This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.5. An app may be able to gain root privileges.
nvd
CVE-2024-40861P3HIGHCVSS 7.8fixed in 15.0fixed in 152024-09-17
CVE-2024-40861 [HIGH] CWE-269 CVE-2024-40861: The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.
nvd
CVE-2025-31188P3HIGHCVSS 7.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-31188 [HIGH] CWE-362 CVE-2025-31188: A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4 A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to bypass Privacy preferences.
nvd
CVE-2024-27848P3HIGHCVSS 7.8≥ 14.0, < 14.5fixed in 14.52024-06-10
CVE-2024-27848 [HIGH] CWE-863 CVE-2024-27848: This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPa This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.
nvd
CVE-2025-43476P3HIGHCVSS 7.8≥ 14.0, < 14.8.2≥ 15.0, < 15.7.2+3 more2025-11-04
CVE-2025-43476 [HIGH] CWE-284 CVE-2025-43476: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to break out of its sandbox.
nvd
CVE-2017-13892P3HIGHCVSS 7.5fixed in 10.13.2≥ unspecified, < 10.132021-12-23
CVE-2017-13892 [HIGH] CVE-2017-13892: An issue existed in the handling of Contact sharing. This issue was addressed with improved handling An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may lead to unexpected data sharing.
nvd
CVE-2025-43364P3HIGHCVSS 7.8≥ 14.0, < 14.8≥ 15.0, < 15.7+3 more2025-11-04
CVE-2025-43364 [HIGH] CWE-362 CVE-2025-43364: A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7 A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.1. An app may be able to break out of its sandbox.
nvd
Apple macOS vulnerabilities | cvebase