Apple macOS vulnerabilities
3,438 known vulnerabilities affecting apple/macos.
Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152
Vulnerabilities
Page 90 of 172
CVE-2022-22662P4MEDIUMCVSS 6.5≥ 11.0, < 11.6.5≥ unspecified, < 11.6+1 more2022-05-26
CVE-2022-22662 [MEDIUM] CVE-2022-22662: A cookie management issue was addressed with improved state management. This issue is fixed in Secur
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2021-1820P4MEDIUMCVSS 6.5≥ 11.0, < 11.3≥ unspecified, < 11.32021-09-08
CVE-2021-1820 [MEDIUM] CWE-665 CVE-2021-1820: A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2021-30755P4MEDIUMCVSS 6.5≥ 11.0, < 11.4≥ unspecified, < 11.4+2 more2021-09-08
CVE-2021-30755 [MEDIUM] CWE-125 CVE-2021-30755: Processing a maliciously crafted font may result in the disclosure of process memory. This issue is
Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5. An out-of-bounds read was addressed with improved input validation.
nvd
CVE-2025-24131P4MEDIUMCVSS 6.5fixed in 15.3fixed in 13.7.5+1 more2025-01-27
CVE-2025-24131 [MEDIUM] CWE-120 CVE-2025-24131: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2023-40420P4MEDIUMCVSS 6.5≥ 12.0.0, < 12.7≥ 13.0, < 13.6+3 more2023-09-27
CVE-2023-40420 [MEDIUM] CVE-2023-40420: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to a denial-of-service.
nvd
CVE-2023-40403P4MEDIUMCVSS 6.5≥ 12.0.0, < 12.7≥ 13.0, < 13.6+3 more2023-09-27
CVE-2023-40403 [MEDIUM] CVE-2023-40403: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.
nvd
CVE-2023-38133P4MEDIUMCVSS 6.5≥ 13.0, < 13.5≥ unspecified, < 13.52023-07-27
CVE-2023-38133 [MEDIUM] CVE-2023-38133: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, i
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may disclose sensitive information.
nvd
CVE-2025-31192P4MEDIUMCVSS 6.7≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-31192 [MEDIUM] CWE-305 CVE-2025-31192: The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.
nvd
CVE-2025-43216P4MEDIUMCVSS 6.5fixed in 15.62025-07-30
CVE-2025-43216 [MEDIUM] CWE-416 CVE-2025-43216: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2024-40782P4MEDIUMCVSS 6.5≥ 14.0, < 14.6fixed in 14.62024-07-29
CVE-2024-40782 [MEDIUM] CWE-416 CVE-2024-40782: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-43212P4MEDIUMCVSS 6.5fixed in 15.62025-07-30
CVE-2025-43212 [MEDIUM] CWE-119 CVE-2025-43212: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43272P4MEDIUMCVSS 6.5fixed in 26.0fixed in 262025-09-15
CVE-2025-43272 [MEDIUM] CWE-119 CVE-2025-43272: The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2022-32923P4MEDIUMCVSS 6.5fixed in 13.0≥ unspecified, < 132022-11-01
CVE-2022-32923 [MEDIUM] CWE-79 CVE-2022-32923: A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1,
A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.
nvd
CVE-2024-27878P4MEDIUMCVSS 6.7≥ 14.0, < 14.6fixed in 14.62024-07-29
CVE-2024-27878 [MEDIUM] CWE-120 CVE-2024-27878: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS So
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2020-27893P4MEDIUMCVSS 6.5fixed in 11.0.1≥ unspecified, < 11.02021-04-02
CVE-2020-27893 [MEDIUM] CVE-2020-27893: An issue existed in screen sharing. This issue was addressed with improved state management. This is
An issue existed in screen sharing. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A user with screen sharing access may be able to view another user's screen.
nvd
CVE-2025-24143P4MEDIUMCVSS 6.5fixed in 15.32025-01-27
CVE-2025-24143 [MEDIUM] CWE-862 CVE-2025-24143: The issue was addressed with improved access restrictions to the file system. This issue is fixed in
The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.
nvd
CVE-2022-42830P4MEDIUMCVSS 6.7fixed in 13.0≥ unspecified, < 13+1 more2022-11-01
CVE-2022-42830 [MEDIUM] CWE-787 CVE-2022-42830: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2021-1855P4MEDIUMCVSS 6.5≥ 11.0, < 11.3≥ unspecified, < 11.32021-09-08
CVE-2021-1855 [MEDIUM] CVE-2021-1855: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to force unnecessary network connections to fetch its favicon.
nvd
CVE-2019-8736P4MEDIUMCVSS 6.5≥ unspecified, < 10.152020-10-27
CVE-2019-8736 [MEDIUM] CWE-20 CVE-2019-8736: An input validation issue was addressed with improved input validation. This issue is fixed in macOS
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Catalina 10.15. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2019-8645P4MEDIUMCVSS 6.5≥ unspecified, < 10.142020-10-27
CVE-2019-8645 [MEDIUM] CVE-2019-8645: An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation
An issue existed in the handling of encrypted Mail. This issue was addressed with improved isolation of MIME in Mail. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. An attacker in a privileged network position may be able to intercept the contents of S/MIME-encrypted e-mail.
nvd