Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 10 of 48
CVE-2025-24156P3HIGHCVSS 7.8v14.7.32025-01-27
CVE-2025-24156 [HIGH] CVE-2025-24156: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24156
Component: Xsan
Impact: An app may be able to elevate privileges
Description: An integer overflow was addressed through improved input validation.
apple
CVE-2025-7424P3HIGHCVSS 7.5v14.7.72025-07-29
CVE-2025-7424 [HIGH] CVE-2025-7424: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-7424
Component: LaunchServices
Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges
Description: This issue was addressed through improved state management.
apple
CVE-2023-42856P3HIGHCVSS 7.8v14.12023-10-25
CVE-2023-42856 [HIGH] CVE-2023-42856: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42856
Component: Model I/O
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-40432P3HIGHCVSS 7.8v142023-09-26
CVE-2023-40432 [HIGH] CVE-2023-40432: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40432
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-42882P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42882 [HIGH] CVE-2023-42882: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42882
Component: AppleVA
Impact: Processing an image may lead to arbitrary code execution
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-23288P3HIGHCVSS 7.8v14.42024-03-07
CVE-2024-23288 [HIGH] CVE-2024-23288: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23288
Component: AppleMobileFileIntegrity
Impact: An app may be able to elevate privileges
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2023-40446P3HIGHCVSS 7.8v14.12023-10-25
CVE-2023-40446 [HIGH] CVE-2023-40446: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-40446
Component: LaunchServices
Impact: An app may be able to access sensitive user data
Description: The issue was addressed with improved permissions logic.
apple
CVE-2026-20611P3HIGHCVSS 7.8v14.8.42026-02-11
CVE-2026-20611 [HIGH] CVE-2026-20611: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20611
Component: CoreAudio
Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory
Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2025-24277P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24277 [HIGH] CVE-2025-24277: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24277
Component: Crash Reporter
Impact: An app may be able to gain root privileges
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2023-40401P3HIGHCVSS 7.5v142023-09-26
CVE-2023-40401 [HIGH] CVE-2023-40401: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40401
Component: Passkeys
Impact: An attacker may be able to access passkeys without authentication
Description: The issue was addressed with additional permissions checks.
apple
CVE-2023-42873P3HIGHCVSS 7.8v14.12023-10-25
CVE-2023-42873 [HIGH] CVE-2023-42873: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42873
Component: Pro Res
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-24267P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24267 [HIGH] CVE-2025-24267: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24267
Component: DiskArbitration
Impact: An app may be able to gain root privileges
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42871P3HIGHCVSS 7.8v142023-09-26
CVE-2023-42871 [HIGH] CVE-2023-42871: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42871
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43402P3HIGHCVSS 7.8v14.8.42026-02-11
CVE-2025-43402 [HIGH] CVE-2025-43402: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-43402
Component: WindowServer
Impact: An app may be able to cause unexpected system termination or corrupt process memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43223P3HIGHCVSS 7.5v14.7.72025-07-29
CVE-2025-43223 [HIGH] CVE-2025-43223: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43223
Component: CFNetwork
Impact: A non-privileged user may be able to modify restricted network settings
Description: A denial-of-service issue was addressed with improved input validation.
apple
CVE-2025-43361P3HIGHCVSS 7.8v14.8.22025-11-03
CVE-2025-43361 [HIGH] CVE-2025-43361: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43361
Component: Audio
Impact: A malicious app may be able to read kernel memory
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2025-43401P3HIGHCVSS 7.5v14.8.22025-11-03
CVE-2025-43401 [HIGH] CVE-2025-43401: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43401
Component: CoreAnimation
Impact: A remote attacker may be able to cause a denial-of-service
Description: A denial-of-service issue was addressed with improved validation.
apple
CVE-2025-43474P3HIGHCVSS 7.8v14.8.22025-11-03
CVE-2025-43474 [HIGH] CVE-2025-43474: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43474
Component: GPU Drivers
Impact: An app may be able to cause unexpected system termination or read kernel memory
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2025-43286P3HIGHCVSS 7.8v14.82025-09-15
CVE-2025-43286 [HIGH] CVE-2025-43286: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43286
Component: SharedFileList
Impact: An app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24258P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-24258 [HIGH] CVE-2025-24258: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-24258
Component: DiskArbitration
Impact: An app may be able to gain root privileges
Description: A permissions issue was addressed with additional restrictions.
apple