Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 84 of 172
CVE-2024-23284P3MEDIUMCVSS 6.5≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23284 [MEDIUM] CWE-693 CVE-2024-23284: A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2026-43693P3HIGHCVSS 7.0≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-43693 [HIGH] CWE-362 CVE-2026-43693: A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
nvd
CVE-2024-2466P3MEDIUMCVSS 6.5fixed in 12.7.6≥ 13.0, < 13.6.8+1 more2024-03-27
CVE-2024-2466 [MEDIUM] CWE-297 CVE-2024-2466: libcurl did not check the server certificate of TLS connections done to a host specified as an IP ad
libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTP
nvd
CVE-2026-28878P3MEDIUMCVSS 6.5≥ 14.0, < 14.8.5≥ 26.0, < 26.4+3 more2026-03-25
CVE-2026-28878 [MEDIUM] CWE-200 CVE-2026-28878: A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPad
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.7, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to enumerate a user's installed apps.
nvd
CVE-2024-44294P3MEDIUMCVSS 6.5fixed in 13.7.1≥ 14.0, < 14.7.1+2 more2024-10-28
CVE-2024-44294 [MEDIUM] CVE-2024-44294: A path deletion vulnerability was addressed by preventing vulnerable code from running with privileg
A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker with root privileges may be able to delete protected system files.
nvd
CVE-2025-24239P3MEDIUMCVSS 6.5fixed in 15.42025-03-31
CVE-2025-24239 [MEDIUM] CWE-200 CVE-2025-24239: A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in ma
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
nvd
CVE-2022-1927P4HIGHCVSS 7.8fixed in 13.02022-05-29
CVE-2022-1927 [HIGH] CWE-126 CVE-2022-1927: Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-0554P3HIGHCVSS 7.8fixed in 13.02022-02-10
CVE-2022-0554 [HIGH] CWE-823 CVE-2022-0554: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2024-44133P4MEDIUMCVSS 5.5fixed in 15.0fixed in 152024-09-17
CVE-2024-44133 [MEDIUM] CVE-2024-44133: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15. O
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15. On MDM managed devices, an app may be able to bypass certain Privacy preferences.
nvd
CVE-2022-0368P4HIGHCVSS 7.8≥ 12.0, < 12.62022-01-26
CVE-2022-0368 [HIGH] CWE-125 CVE-2022-0368: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-1735P4HIGHCVSS 7.8fixed in 13.02022-05-17
CVE-2022-1735 [HIGH] CWE-120 CVE-2022-1735: Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.
Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.
nvd
CVE-2018-4451P3HIGHCVSS 7.8≥ unspecified, < 10.142020-10-27
CVE-2018-4451 [HIGH] CVE-2018-4451: This issue is fixed in macOS Mojave 10.14. A memory corruption issue was addressed with improved inp
This issue is fixed in macOS Mojave 10.14. A memory corruption issue was addressed with improved input validation.
nvd
CVE-2020-9788P4HIGHCVSS 7.8≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9788 [HIGH] CWE-20 CVE-2020-9788: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Cata
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.5. A file may be incorrectly rendered to execute JavaScript.
nvd
CVE-2023-4781P3HIGHCVSS 7.8fixed in 14.12023-09-05
CVE-2023-4781 [HIGH] CWE-122 CVE-2023-4781: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
nvd
CVE-2023-4738P4HIGHCVSS 7.8v14.02023-09-02
CVE-2023-4738 [HIGH] CWE-122 CVE-2023-4738: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
nvd
CVE-2023-4751P3HIGHCVSS 7.8v14.02023-09-03
CVE-2023-4751 [HIGH] CWE-122 CVE-2023-4751: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
nvd
CVE-2023-4752P4HIGHCVSS 7.8fixed in 14.12023-09-04
CVE-2023-4752 [HIGH] CWE-416 CVE-2023-4752: Use After Free in GitHub repository vim/vim prior to 9.0.1858.
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
nvd
CVE-2023-4733P4HIGHCVSS 7.8fixed in 14.12023-09-04
CVE-2023-4733 [HIGH] CWE-416 CVE-2023-4733: Use After Free in GitHub repository vim/vim prior to 9.0.1840.
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
nvd
CVE-2023-4750P4HIGHCVSS 7.8fixed in 14.12023-09-04
CVE-2023-4750 [HIGH] CWE-416 CVE-2023-4750: Use After Free in GitHub repository vim/vim prior to 9.0.1857.
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
nvd
CVE-2020-9826P4HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9826 [HIGH] CWE-20 CVE-2020-9826: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1
A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause a denial of service.
nvd