Apple macOS vulnerabilities

3,135 known vulnerabilities affecting apple/macos.

Total CVEs
3,135
CISA KEV
75
actively exploited
Public exploits
44
Exploited in wild
61
Severity breakdown
CRITICAL203HIGH1362MEDIUM1421LOW149

Vulnerabilities

Page 98 of 157
CVE-2022-32832MEDIUMCVSS 6.7fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32832 [MEDIUM] CVE-2022-32832: The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15 The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-32805MEDIUMCVSS 5.5fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-09-23
CVE-2022-32805 [MEDIUM] CWE-200 CVE-2022-32805: The issue was addressed with improved handling of caches. This issue is fixed in Security Update 202 The issue was addressed with improved handling of caches. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to access sensitive user information.
nvd
CVE-2022-32817MEDIUMCVSS 5.5≥ 12.0, < 12.5≥ unspecified, < 12.52022-09-23
CVE-2022-32817 [MEDIUM] CWE-125 CVE-2022-32817: An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watc An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
nvd
CVE-2022-26707MEDIUMCVSS 5.5≥ 12.0.0, < 12.4≥ unspecified, < 12.42022-09-23
CVE-2022-26707 [MEDIUM] CWE-20 CVE-2022-26707: An issue in the handling of environment variables was addressed with improved validation. This issue An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in macOS Monterey 12.4. A user may be able to view sensitive user information.
nvd
CVE-2022-35252LOWCVSS 3.7≥ 11.0, < 11.7.3≥ 12.0.0, < 12.6.32022-09-23
CVE-2022-35252 [LOW] CWE-20 CVE-2022-35252: When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using contr When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
nvd
CVE-2022-32863CRITICALCVSS 9.8≥ 12.0.0, < 12.5≥ unspecified, < 12.5+1 more2022-09-20
CVE-2022-32863 [CRITICAL] CWE-787 CVE-2022-32863: A memory corruption issue was addressed with improved state management. This issue is fixed in Safar A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-32882CRITICALCVSS 9.8≥ 11.0, < 11.6.6≥ 12.0.0, < 12.4+2 more2022-09-20
CVE-2022-32882 [CRITICAL] CVE-2022-32882: This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-32788CRITICALCVSS 9.8≥ 12.0.0, < 12.5≥ unspecified, < 12.52022-09-20
CVE-2022-32788 [CRITICAL] CWE-120 CVE-2022-32788: A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, t A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.
nvd
CVE-2022-26696HIGHCVSS 8.8≥ 12.0.0, < 12.4≥ unspecified, < 12.42022-09-20
CVE-2022-26696 [HIGH] CWE-693 CVE-2022-26696: This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monter This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2022-32917HIGHCVSS 7.8KEV≥ 11.0, < 11.7≥ 12.0.0, < 12.6+3 more2022-09-20
CVE-2022-32917 [HIGH] CWE-787 CVE-2022-32917: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2022-32908HIGHCVSS 7.8≥ 11.0, < 11.7≥ 12.0.0, < 12.6+3 more2022-09-20
CVE-2022-32908 [HIGH] CWE-787 CVE-2022-32908: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. A user may be able to elevate privileges.
nvd
CVE-2022-32911HIGHCVSS 7.8≥ 11.0, < 11.7≥ 12.0.0, < 12.6+3 more2022-09-20
CVE-2022-32911 [HIGH] CWE-787 CVE-2022-32911: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, i The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-32802HIGHCVSS 7.8≥ 12.0.0, < 12.5≥ unspecified, < 12.52022-09-20
CVE-2022-32802 [HIGH] CWE-693 CVE-2022-32802: A logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, t A logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted file may lead to arbitrary code execution.
nvd
CVE-2022-32861MEDIUMCVSS 5.3≥ 12.0.0, < 12.5≥ unspecified, < 12.5+1 more2022-09-20
CVE-2022-32861 [MEDIUM] CVE-2022-32861: A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macO A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A user may be tracked through their IP address.
nvd
CVE-2022-32864MEDIUMCVSS 5.5≥ 11.0, < 11.7≥ 12.0.0, < 12.6+3 more2022-09-20
CVE-2022-32864 [MEDIUM] CVE-2022-32864: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, i The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to disclose kernel memory.
nvd
CVE-2022-32854MEDIUMCVSS 5.5≥ 11.0.0, < 11.7≥ unspecified, < 11.7+1 more2022-09-20
CVE-2022-32854 [MEDIUM] CVE-2022-32854: This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-32883MEDIUMCVSS 5.5≥ 11.0, < 11.7≥ 12.0.0, < 12.6+3 more2022-09-20
CVE-2022-32883 [MEDIUM] CWE-284 CVE-2022-32883: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to read sensitive location information.
nvd
CVE-2022-32880MEDIUMCVSS 6.5≥ 12.0.0, < 12.5≥ unspecified, < 12.52022-09-20
CVE-2022-32880 [MEDIUM] CWE-284 CVE-2022-32880: This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. A This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to access user-sensitive data.
nvd
CVE-2022-32839CRITICALCVSS 9.8fixed in 10.15.7≥ 11.0, < 11.6.8+5 more2022-08-24
CVE-2022-32839 [CRITICAL] CWE-119 CVE-2022-32839: The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, mac The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.
nvd
CVE-2022-32894HIGHCVSS 7.8KEV≥ 11.0, < 11.7≥ 12.0, < 12.5.1+1 more2022-08-24
CVE-2022-32894 [HIGH] CWE-787 CVE-2022-32894: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
nvd