cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 97 of 172
CVE-2025-24192P4MEDIUMCVSS 6.5≥ 15.0, < 15.4fixed in 15.42025-03-31
CVE-2025-24192 [MEDIUM] CVE-2025-24192: A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iO A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data.
nvd
CVE-2023-28187P4MEDIUMCVSS 6.5≥ 13.0, < 13.3≥ unspecified, < 13.32023-09-06
CVE-2023-28187 [MEDIUM] CVE-2023-28187: This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3. This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3. A user may be able to cause a denial-of-service.
nvd
CVE-2022-32880P4MEDIUMCVSS 6.5≥ 12.0.0, < 12.5≥ unspecified, < 12.52022-09-20
CVE-2022-32880 [MEDIUM] CWE-284 CVE-2022-32880: This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. A This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data.
nvd
CVE-2025-24188P4MEDIUMCVSS 6.5fixed in 15.62025-07-30
CVE-2025-24188 [MEDIUM] CWE-703 CVE-2025-24188: A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-43663P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-43663 [MEDIUM] CWE-119 CVE-2026-43663: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-39872P4MEDIUMCVSS 6.5fixed in 26.5.22026-06-29
CVE-2026-39872 [MEDIUM] CWE-119 CVE-2026-39872: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26. The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2021-30722P4MEDIUMCVSS 5.9≥ 11.0.1, < 11.4≥ unspecified, < 11.4+1 more2021-09-08
CVE-2021-30722 [MEDIUM] CVE-2021-30722: An information disclosure issue was addressed with improved state management. This issue is fixed in An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. An attacker in a privileged network position may be able to leak sensitive user information.
nvd
CVE-2022-32799P4MEDIUMCVSS 5.9fixed in 10.15.7≥ 12.0, < 12.5+3 more2022-09-23
CVE-2022-32799 [MEDIUM] CWE-125 CVE-2022-32799: An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Secu An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. A user in a privileged network position may be able to leak sensitive information.
nvd
CVE-2024-54492P4MEDIUMCVSS 5.9fixed in 15.22024-12-12
CVE-2024-54492 [MEDIUM] CVE-2024-54492: This issue was addressed by using HTTPS when sending information over the network. This issue is fix This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.
nvd
CVE-2025-24157P4MEDIUMCVSS 5.6fixed in 13.7.5≥ 14.0, < 14.7.5+3 more2025-03-31
CVE-2025-24157 [MEDIUM] CWE-120 CVE-2025-24157: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Se A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2023-42898P4MEDIUMCVSS 5.5≥ 14.0, < 14.2≥ unspecified, < 14.22023-12-12
CVE-2023-42898 [MEDIUM] CVE-2023-42898: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, wat The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing an image may lead to arbitrary code execution.
nvd
CVE-2021-36976P4MEDIUMCVSS 6.5fixed in 12.32021-07-20
CVE-2021-36976 [MEDIUM] CWE-416 CVE-2021-36976: libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
nvd
CVE-2021-30788P4HIGHCVSS 7.1fixed in 11.5≥ unspecified, < 11.5+3 more2021-09-08
CVE-2021-30788 [HIGH] CVE-2021-30788: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2020-9842P4HIGHCVSS 7.1≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9842 [HIGH] CVE-2020-9842: An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 an An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application could interact with system processes to access private information and perform privileged actions.
nvd
CVE-2020-9808P4HIGHCVSS 7.1≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9808 [HIGH] CWE-787 CVE-2020-9808: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2020-13630P4HIGHCVSS 7.0fixed in 11.0.12020-05-27
CVE-2020-13630 [HIGH] CWE-416 CVE-2020-13630: ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snip ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
nvd
CVE-2020-3855P4HIGHCVSS 7.1≥ unspecified, < 10.152020-10-27
CVE-2020-3855 [HIGH] CVE-2020-3855: An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catali An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra. A malicious application may be able to overwrite arbitrary files.
nvd
CVE-2022-32843P4HIGHCVSS 7.1fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32843 [HIGH] CWE-787 CVE-2022-32843: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Sec An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted Postscript file may result in unexpected app termination or disclosure of process memory.
nvd
CVE-2026-20687P4HIGHCVSS 7.1≥ 15.0, < 15.7.5≥ 26.0, < 26.4+2 more2026-03-25
CVE-2026-20687 [HIGH] CWE-416 CVE-2026-20687: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2025-43224P4HIGHCVSS 7.1fixed in 15.62025-07-30
CVE-2025-43224 [HIGH] CWE-787 CVE-2025-43224: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvd
Apple macOS vulnerabilities | cvebase