Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 83 of 172
CVE-2019-8509P3HIGHCVSS 7.8≥ unspecified, < 10.152020-10-27
CVE-2019-8509 [HIGH] CVE-2019-8509: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.1
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. A malicious application may be able to elevate privileges.
nvd
CVE-2020-29620P3HIGHCVSS 7.8≥ 11.0, < 11.1.0≥ unspecified, < 11.12021-04-02
CVE-2020-29620 [HIGH] CWE-269 CVE-2020-29620: This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.1, Secu
This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to elevate privileges.
nvd
CVE-2019-8755P3HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.152019-12-18
CVE-2019-8755 [HIGH] CWE-476 CVE-2019-8755: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2019-8618P3HIGHCVSS 7.5≥ unspecified, < 10.14≥ unspecified, < 5.22020-10-27
CVE-2019-8618 [HIGH] CVE-2019-8618: A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mo
A logic issue was addressed with improved restrictions. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2019-8533P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8533 [HIGH] CWE-287 CVE-2019-8533: A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave
A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave 10.14.4. A Mac may not lock when disconnecting from an external monitor.
nvd
CVE-2024-23244P3HIGHCVSS 7.8≥ 12.0, < 12.7.4≥ 14.0, < 14.4+2 more2024-03-08
CVE-2024-23244 [HIGH] CVE-2024-23244: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.7.4
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4. An app from a standard user account may be able to escalate privilege after admin user login.
nvd
CVE-2023-27960P3HIGHCVSS 7.8≥ unspecified, < 10.42023-05-08
CVE-2023-27960 [HIGH] CVE-2023-27960: This issue was addressed by removing the vulnerable code. This issue is fixed in GarageBand for macO
This issue was addressed by removing the vulnerable code. This issue is fixed in GarageBand for macOS 10.4.8. An app may be able to gain elevated privileges during the installation of GarageBand.
nvd
CVE-2023-42977P3HIGHCVSS 7.8fixed in 14.0≥ unspecified, < 142025-04-11
CVE-2023-42977 [HIGH] CWE-20 CVE-2023-42977: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPad
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.
nvd
CVE-2023-42933P3HIGHCVSS 7.8fixed in 14.0≥ unspecified, < 142024-01-10
CVE-2023-42933 [HIGH] CVE-2023-42933: This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to gain elevated privileges.
nvd
CVE-2025-43340P3HIGHCVSS 7.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43340 [HIGH] CWE-284 CVE-2025-43340: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.
nvd
CVE-2023-42958P3HIGHCVSS 7.8≥ 13.0, < 13.4≥ unspecified, < 13.42024-07-29
CVE-2023-42958 [HIGH] CVE-2023-42958: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.4. An app may be able to gain elevated privileges.
nvd
CVE-2021-30938P3HIGHCVSS 7.7≥ 11.0, < 11.6.2≥ 12.0.0, ≤ 12.1+3 more2021-08-24
CVE-2021-30938 [HIGH] CVE-2021-30938: This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.1, Security
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2020-9824P3HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9824 [HIGH] CVE-2020-9824: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A non-privileged user may be able to modify restricted network settings.
nvd
CVE-2026-43725P3HIGHCVSS 7.1≥ 26.0, < 26.5.2fixed in 26.5.22026-06-29
CVE-2026-43725 [HIGH] CWE-20 CVE-2026-43725: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2024-54533P3HIGHCVSS 7.0fixed in 13.7.5≥ 14.0, < 14.7.5+2 more2025-03-31
CVE-2024-54533 [HIGH] CWE-284 CVE-2024-54533: A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access sensitive user data.
nvd
CVE-2019-8597P3MEDIUMCVSS 6.5≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8597 [MEDIUM] CWE-787 CVE-2019-8597: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-8615P3MEDIUMCVSS 6.5≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8615 [MEDIUM] CWE-125 CVE-2019-8615: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-1799P3MEDIUMCVSS 6.5≥ 11.0.1, < 11.2≥ unspecified, < 11.2+3 more2021-04-02
CVE-2021-1799 [MEDIUM] CVE-2021-1799: A port redirection issue was addressed with additional port validation. This issue is fixed in macOS
A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. A malicious website may be able to access restricted ports on arbitrary servers.
nvd
CVE-2025-31249P3HIGHCVSS 7.1fixed in 15.52025-05-12
CVE-2025-31249 [HIGH] CWE-285 CVE-2025-31249: A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.
nvd
CVE-2024-23263P3MEDIUMCVSS 6.5≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23263 [MEDIUM] CWE-20 CVE-2024-23263: A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd