cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 85 of 172
CVE-2022-1769P4HIGHCVSS 7.8fixed in 13.02022-05-17
CVE-2022-1769 [HIGH] CWE-126 CVE-2022-1769: Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974. Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.
nvd
CVE-2022-32205P4MEDIUMCVSS 4.3fixed in 13.02022-07-07
CVE-2022-32205 [MEDIUM] CWE-770 CVE-2022-32205: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl a A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to av
nvd
CVE-2019-8851P4HIGHCVSS 7.5≥ unspecified, < 10.152020-10-27
CVE-2019-8851 [HIGH] CVE-2019-8851: A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10 A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A Mac may not lock immediately upon wake.
nvd
CVE-2024-23233P4HIGHCVSS 7.8≥ 14.0, < 14.4fixed in 14.42024-03-08
CVE-2024-23233 [HIGH] CWE-277 CVE-2024-23233: This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlement This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
nvd
CVE-2022-48683P4HIGHCVSS 7.8fixed in 13.0≥ unspecified, < 132024-06-10
CVE-2022-48683 [HIGH] CWE-284 CVE-2022-48683: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ven An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its sandbox.
nvd
CVE-2023-34241P4HIGHCVSS 7.1fixed in 11.7.9≥ 12.0.0, < 12.6.8+1 more2023-06-22
CVE-2023-34241 [HIGH] CWE-416 CVE-2023-34241: OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like op OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that impacts
nvd
CVE-2021-30857P4HIGHCVSS 7.0≥ 11.0, < 11.6≥ unspecified, < 11.6+4 more2021-08-24
CVE-2021-30857 [HIGH] CWE-362 CVE-2021-30857: A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-00 A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-28825P4HIGHCVSS 7.1≥ 14.0, < 14.8.5≥ 15.0, < 15.7.5+4 more2026-03-25
CVE-2026-28825 [HIGH] CWE-787 CVE-2026-28825: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in mac An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.
nvd
CVE-2022-32832P3MEDIUMCVSS 6.7fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32832 [MEDIUM] CVE-2022-32832: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15 The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-43755P4HIGHCVSS 7.0≥ 14.0, < 14.8.8≥ 26.0, < 26.6+2 more2026-07-27
CVE-2026-43755 [HIGH] CWE-362 CVE-2026-43755: A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 1 A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
nvd
CVE-2023-40416P4MEDIUMCVSS 6.5≥ 12.0.0, < 12.7.1≥ 13.0, < 13.6.1+4 more2023-10-25
CVE-2023-40416 [MEDIUM] CWE-119 CVE-2023-40416: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. Processing an image may result in disclosure of process memory.
nvd
CVE-2019-8612P4MEDIUMCVSS 6.5≥ unspecified, < 10.14≥ unspecified, < 12.3+1 more2020-10-27
CVE-2019-8612 [MEDIUM] CVE-2019-8612: A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.1 A logic issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, tvOS 12.3, watchOS 5.2.1, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. An attacker in a privileged network position can modify
nvd
CVE-2025-30446P4MEDIUMCVSS 6.5≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-30446 [MEDIUM] CWE-787 CVE-2025-30446: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app with root privileges may be able to modify the contents of system files.
nvd
CVE-2024-44248P4MEDIUMCVSS 6.5≥ 13.0, < 13.7.2≥ 14.0, < 14.7.2+3 more2024-12-12
CVE-2024-44248 [MEDIUM] CVE-2024-44248: This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15. This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A user with screen sharing access may be able to view another user's screen.
nvd
CVE-2026-43707P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43707 [MEDIUM] CWE-119 CVE-2026-43707: A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43745P4MEDIUMCVSS 6.5≥ 26.0, < 26.5.2fixed in 26.5.22026-06-29
CVE-2026-43745 [MEDIUM] CWE-787 CVE-2026-43745: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Sa An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2023-42861P4MEDIUMCVSS 6.5≥ 14.0, < 14.1≥ unspecified, < 14.12023-10-25
CVE-2023-42861 [MEDIUM] CWE-732 CVE-2023-42861: A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1 A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's credentials can unlock another standard user's locked screen on the same Mac.
nvd
CVE-2025-43457P4MEDIUMCVSS 6.5fixed in 26.12025-11-04
CVE-2025-43457 [MEDIUM] CWE-416 CVE-2025-43457: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-46287P4MEDIUMCVSS 6.5≥ 14.0, < 14.8.3≥ 15.0, < 15.7.3+3 more2025-12-12
CVE-2025-46287 [MEDIUM] CWE-451 CVE-2025-46287: An inconsistent user interface issue was addressed with improved state management. This issue is fix An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An attacker may be able to spoof their FaceTime caller ID.
nvd
CVE-2026-43732P3MEDIUMCVSS 6.5≥ 26.0, < 26.5.2fixed in 26.5.22026-06-29
CVE-2026-43732 [MEDIUM] CWE-22 CVE-2026-43732: A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
nvd
Apple macOS vulnerabilities | cvebase