Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 78 of 172
CVE-2021-31005P3HIGHCVSS 7.5v12.0.0≥ unspecified, < 12.02021-08-24
CVE-2021-31005 [HIGH] CVE-2021-31005: Description: A logic issue was addressed with improved state management. This issue is fixed in iOS
Description: A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, macOS Monterey 12.0.1. Turning off "Block all remote content" may not apply to all remote content types.
nvd
CVE-2025-24177P3HIGHCVSS 7.5≥ 15.0, < 15.3fixed in 13.7.5+2 more2025-01-27
CVE-2025-24177 [HIGH] CWE-476 CVE-2025-24177: A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2018-4296P3CRITICALCVSS 9.8≥ unspecified, < 10.142020-10-27
CVE-2018-4296 [CRITICAL] CVE-2018-4296: This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was
This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks.
nvd
CVE-2020-9774P3HIGHCVSS 7.5≥ unspecified, < 10.152020-10-27
CVE-2020-9774 [HIGH] CWE-311 CVE-2020-9774: An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting acc
An issue existed with Siri Suggestions access to encrypted data. The issue was fixed by limiting access to encrypted data. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. Encrypted data may be inappropriately accessed.
nvd
CVE-2023-42869P3HIGHCVSS 7.5fixed in 13.4≥ unspecified, < 13.42024-01-10
CVE-2023-42869 [HIGH] CWE-787 CVE-2023-42869: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Ventura 13.4, iOS 16.5 and iPadOS 16.5. Multiple issues in libxml2.
nvd
CVE-2024-27795P3HIGHCVSS 7.5fixed in 15.0fixed in 152024-09-17
CVE-2024-27795 [HIGH] CWE-281 CVE-2024-27795: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the internet.
nvd
CVE-2024-40770P3HIGHCVSS 7.5fixed in 15.0fixed in 152024-09-17
CVE-2024-40770 [HIGH] CWE-281 CVE-2024-40770: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted network settings.
nvd
CVE-2025-24259P3CRITICALCVSS 9.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24259 [CRITICAL] CWE-284 CVE-2025-24259: This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, m
This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
nvd
CVE-2025-43243P3CRITICALCVSS 9.8fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43243 [CRITICAL] CWE-732 CVE-2025-43243: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.
nvd
CVE-2025-43506P3HIGHCVSS 7.5fixed in 26.12025-12-12
CVE-2025-43506 [HIGH] CWE-843 CVE-2025-43506: A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. i
A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay may not activate when more than one user is logged in at the same time.
nvd
CVE-2025-43244P3CRITICALCVSS 9.8fixed in 13.7.7≥ 14.0, < 14.7.7+3 more2025-07-30
CVE-2025-43244 [CRITICAL] CWE-362 CVE-2025-43244: A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.
nvd
CVE-2025-31219P3HIGHCVSS 7.1fixed in 13.7.6≥ 14.0, < 14.7.6+3 more2025-05-12
CVE-2025-31219 [HIGH] CWE-119 CVE-2025-31219: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2023-41076P3HIGHCVSS 7.3fixed in 14.0≥ unspecified, < 142025-04-11
CVE-2023-41076 [HIGH] CWE-269 CVE-2023-41076: An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed
An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.
nvd
CVE-2024-54486P3MEDIUMCVSS 6.5fixed in 13.7.2≥ 14.0, < 14.7.2+3 more2024-12-12
CVE-2024-54486 [MEDIUM] CVE-2024-54486: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2019-8603P3HIGHCVSS 8.8≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8603 [HIGH] CWE-125 CVE-2019-8603: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5. An application may be able to read restricted memory.
nvd
CVE-2023-28182P3MEDIUMCVSS 6.5≥ 11.0, < 11.7.5≥ 12.0, < 12.6.4+4 more2023-05-08
CVE-2023-28182 [MEDIUM] CWE-287 CVE-2023-28182: The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS
The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position may be able to spoof a VPN server that is configured with EAP-only authentication on a device.
nvd
CVE-2022-32816P3MEDIUMCVSS 6.5≥ 12.0, < 12.5≥ unspecified, < 12.52022-09-23
CVE-2022-32816 [MEDIUM] CWE-451 CVE-2022-32816: The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iO
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2025-30432P3MEDIUMCVSS 6.4≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+2 more2025-03-31
CVE-2025-30432 [MEDIUM] CWE-287 CVE-2025-30432: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.
nvd
CVE-2025-31209P3MEDIUMCVSS 6.3fixed in 13.7.6≥ 14.0, < 14.7.6+3 more2025-05-12
CVE-2025-31209 [MEDIUM] CWE-125 CVE-2025-31209: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to disclosure of user information.
nvd
CVE-2021-30924P3HIGHCVSS 7.5fixed in 12.0.1≥ unspecified, < 12.02021-08-24
CVE-2021-30924 [HIGH] CVE-2021-30924: A denial of service issue was addressed with improved state handling. This issue is fixed in macOS M
A denial of service issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.0.1. A remote attacker can cause a device to unexpectedly restart.
nvd