Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 11 of 48
CVE-2025-43341P3HIGHCVSS 7.8v14.82025-09-15
CVE-2025-43341 [HIGH] CVE-2025-43341: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43341
Component: Storage
Impact: An app may be able to gain root privileges
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2024-23203P3HIGHCVSS 7.5v14.32024-01-22
CVE-2024-23203 [HIGH] CVE-2024-23203: macOS Sonoma 14.3
Apple Security Update: About the security content of macOS Sonoma 14.3
Product: macOS Sonoma
Version: 14.3
CVE: CVE-2024-23203
Component: Shortcuts
Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user
Description: The issue was addressed with additional permissions checks.
apple
CVE-2024-44305P3HIGHCVSS 7.8v14.62024-07-29
CVE-2024-44305 [HIGH] CVE-2024-44305: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-44305
Component: PackageKit
Impact: An app may be able to gain root privileges
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-24256P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24256 [CRITICAL] CVE-2025-24256: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24256
Component: GPU Drivers
Impact: An app may be able to disclose kernel memory
Description: The issue was addressed with improved bounds checks.
apple
CVE-2023-42847P3HIGHCVSS 7.5v14.12023-10-25
CVE-2023-42847 [HIGH] CVE-2023-42847: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42847
Component: Passkeys
Impact: An attacker may be able to access passkeys without authentication
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-30452P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30452 [CRITICAL] CVE-2025-30452: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30452
Component: Sandbox
Impact: An input validation issue was addressed
Description: The issue was addressed with improved checks.
apple
CVE-2024-44165P3HIGHCVSS 7.5v14.72024-09-16
CVE-2024-44165 [HIGH] CVE-2024-44165: macOS Sonoma 14.7
Apple Security Update: About the security content of macOS Sonoma 14.7
Product: macOS Sonoma
Version: 14.7
CVE: CVE-2024-44165
Component: Kernel
Impact: Network traffic may leak outside a VPN tunnel
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-30465P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30465 [CRITICAL] CVE-2025-30465: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30465
Component: Shortcuts
Impact: A shortcut may be able to access files that are normally inaccessible to the Shortcuts app
Description: A permissions issue was addressed with improved validation.
apple
CVE-2025-24241P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24241 [CRITICAL] CVE-2025-24241: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24241
Component: WindowServer
Impact: An app may be able to trick a user into copying sensitive data to the pasteboard
Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2024-40848P3HIGHCVSS 7.5v14.72024-09-16
CVE-2024-40848 [HIGH] CVE-2024-40848: macOS Sonoma 14.7
Apple Security Update: About the security content of macOS Sonoma 14.7
Product: macOS Sonoma
Version: 14.7
CVE: CVE-2024-40848
Component: AppleMobileFileIntegrity
Impact: An attacker may be able to read sensitive information
Description: A downgrade issue was addressed with additional code-signing restrictions.
apple
CVE-2025-24265P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24265 [CRITICAL] CVE-2025-24265: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24265
Component: Xsan
Impact: An app may be able to cause unexpected system termination
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2025-24172P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24172 [CRITICAL] CVE-2025-24172: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24172
Component: Mail
Impact: "Block All Remote Content" may not apply for all mail previews
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2025-43220P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43220 [CRITICAL] CVE-2025-43220: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43220
Component: CFNetwork
Impact: A non-privileged user may be able to modify restricted network settings
Description: A denial-of-service issue was addressed with improved input validation.
apple
CVE-2025-24249P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24249 [CRITICAL] CVE-2025-24249: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24249
Component: Installer
Impact: An app may be able to check the existence of an arbitrary path on the file system
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2025-43189P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43189 [CRITICAL] CVE-2025-43189: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43189
Component: WebContentFilter
Impact: A malicious app may be able to read kernel memory
Description: This issue was addressed with improved memory handling.
apple
CVE-2025-24229P3HIGHCVSS 7.4v14.7.52025-03-31
CVE-2025-24229 [HIGH] CVE-2025-24229: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24229
Component: Installer
Impact: A sandboxed app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43373P3HIGHCVSS 7.5v14.8.22025-11-03
CVE-2025-43373 [HIGH] CVE-2025-43373: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43373
Component: Wi-Fi
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-49761P3MEDIUMCVSS 6.6v14.8.22025-11-03
CVE-2024-49761 [MEDIUM] CVE-2024-49761: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2024-49761
Component: CVE-2024-49761
apple
CVE-2023-40436P3CRITICALCVSS 9.1v142023-09-26
CVE-2023-40436 [CRITICAL] CVE-2023-40436: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40436
Component: IOAcceleratorFamily
Impact: An attacker may be able to cause unexpected system termination or read kernel memory
Description: The issue was addressed with improved bounds checks.
apple
CVE-2024-23299P3HIGHCVSS 8.6v14.42024-03-07
CVE-2024-23299 [HIGH] CVE-2024-23299: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23299
Component: Disk Images
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved checks.
apple