cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 89 of 172
CVE-2022-26726P4MEDIUMCVSS 6.5≥ 11.0, < 11.6.6≥ 12.0, < 12.42022-05-26
CVE-2022-26726 [MEDIUM] CVE-2022-26726: This issue was addressed with improved checks. This issue is fixed in Security Update 2022-004 Catal This issue was addressed with improved checks. This issue is fixed in Security Update 2022-004 Catalina, watchOS 8.6, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to capture a user's screen.
nvd
CVE-2021-1806P4HIGHCVSS 7.0≥ 11.0, < 11.2.1≥ unspecified, < 11.22021-04-02
CVE-2021-1806 [HIGH] CWE-362 CVE-2021-1806: A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2 A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2026-43701P4HIGHCVSS 7.1fixed in 26.5.22026-06-29
CVE-2026-43701 [HIGH] CWE-284 CVE-2026-43701: The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and i The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2020-27921P4HIGHCVSS 7.0≥ unspecified, < 11.0≥ unspecified, < 11.12021-04-02
CVE-2020-27921 [HIGH] CWE-362 CVE-2020-27921: A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11 A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30868P4HIGHCVSS 7.0≥ 11.0, < 11.6.1v12.0+2 more2021-08-24
CVE-2021-30868 [HIGH] CWE-362 CVE-2021-30868: A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.0.1, A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.0.1, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-30933P4HIGHCVSS 7.0≥ 11.0, < 11.6v12.0.0+2 more2021-08-24
CVE-2021-30933 [HIGH] CWE-362 CVE-2021-30933: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1 A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.0.1, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-22925P4MEDIUMCVSS 5.3v11.0v11.0.1+8 more2021-08-05
CVE-2021-22925 [MEDIUM] CWE-200 CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revea
nvd
CVE-2023-32413P4HIGHCVSS 7.0≥ 11.0, < 11.7.7≥ 12.0, < 12.6.6+4 more2023-06-23
CVE-2023-32413 [HIGH] CWE-362 CVE-2023-32413: A race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvO A race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to gain root privileges.
nvd
CVE-2019-8598P4MEDIUMCVSS 5.5≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8598 [MEDIUM] CWE-119 CVE-2019-8598: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1 An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to read restricted memory.
nvd
CVE-2024-44164P4HIGHCVSS 7.1fixed in 13.7≥ 14.0, < 14.7+2 more2024-09-17
CVE-2024-44164 [HIGH] CVE-2024-44164: This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macO This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to bypass Privacy preferences.
nvd
CVE-2024-54528P4HIGHCVSS 7.1fixed in 13.7.2≥ 14.0, < 14.7.2+3 more2024-12-12
CVE-2024-54528 [HIGH] CVE-2024-54528: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, m A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.
nvd
CVE-2021-30897P4MEDIUMCVSS 6.5fixed in 12.0.1≥ unspecified, < 12.02021-08-24
CVE-2021-30897 [MEDIUM] CVE-2021-30897: An issue existed in the specification for the resource timing API. The specification was updated and An issue existed in the specification for the resource timing API. The specification was updated and the updated specification was implemented. This issue is fixed in macOS Monterey 12.0.1. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2026-43681P4HIGHCVSS 7.1≥ 14.0, < 14.8.8≥ 15.0, < 15.7.8+4 more2026-07-27
CVE-2026-43681 [HIGH] CWE-120 CVE-2026-43681: A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A local user may be able to read kernel memory.
nvd
CVE-2021-30887P4MEDIUMCVSS 6.5fixed in 12.0.1≥ unspecified, < 12.0+2 more2021-08-24
CVE-2021-30887 [MEDIUM] CVE-2021-30887: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy.
nvd
CVE-2022-26758P4HIGHCVSS 7.1fixed in 12.42026-06-10
CVE-2022-26758 [HIGH] CWE-362 CVE-2022-26758: A malicious application may cause unexpected changes in memory shared between processes. A memory co A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4.
nvd
CVE-2020-9796P4HIGHCVSS 7.0≥ unspecified, < macOS Catalina 10.15.52020-10-22
CVE-2020-9796 [HIGH] CWE-362 CVE-2020-9796: A race condition was addressed with improved state handling. This issue is fixed in macOS Catalina 1 A race condition was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42806P4HIGHCVSS 7.0fixed in 13.0≥ unspecified, < 13+1 more2022-11-01
CVE-2022-42806 [HIGH] CWE-362 CVE-2022-42806: A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-8607P4MEDIUMCVSS 6.5≥ unspecified, < macOS Mojave 10.14.52019-12-18
CVE-2019-8607 [MEDIUM] CWE-125 CVE-2019-8607: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2023-42959P4HIGHCVSS 7.0fixed in 14.0≥ unspecified, < 142024-07-29
CVE-2023-42959 [HIGH] CWE-362 CVE-2023-42959: A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-24272P4MEDIUMCVSS 6.8≥ 13.0, < 13.7.5≥ 14.0, < 14.7.5+4 more2025-03-31
CVE-2025-24272 [MEDIUM] CWE-284 CVE-2025-24272: The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonom The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.
nvd
Apple macOS vulnerabilities | cvebase