Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 13 of 48
CVE-2025-43249P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-43249 [HIGH] CVE-2025-43249: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43249
Component: AppleMobileFileIntegrity
Impact: An app may be able to gain root privileges
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43256P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-43256 [HIGH] CVE-2025-43256: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43256
Component: StorageKit
Impact: An app may be able to gain root privileges
Description: This issue was addressed through improved state management.
apple
CVE-2023-42870P3HIGHCVSS 7.8v142023-09-26
CVE-2023-42870 [HIGH] CVE-2023-42870: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42870
Component: Kernel
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-31224P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-31224 [HIGH] CVE-2025-31224: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31224
Component: Sandbox
Impact: An app may be able to bypass certain Privacy preferences
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-30442P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-30442 [HIGH] CVE-2025-30442: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-30442
Component: SoftwareUpdate
Impact: An app may be able to gain elevated privileges
Description: The issue was addressed with improved input sanitization.
apple
CVE-2024-44306P3HIGHCVSS 7.8v14.62024-07-29
CVE-2024-44306 [HIGH] CVE-2024-44306: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-44306
Component: ASP TCP
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2024-44307P3HIGHCVSS 7.8v14.62024-07-29
CVE-2024-44307 [HIGH] CVE-2024-44307: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-44307
Component: ASP TCP
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2024-23261P3HIGHCVSS 7.5v14.42024-03-07
CVE-2024-23261 [HIGH] CVE-2024-23261: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23261
Component: Time Zone
Impact: An attacker may be able to read information belonging to another user
Description: A logic issue was addressed with improved state management.
apple
CVE-2025-24126P3HIGHCVSS 7.3v14.7.52025-03-31
CVE-2025-24126 [HIGH] CVE-2025-24126: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24126
Component: AirPlay
Impact: An attacker on the local network may be able to corrupt process memory
Description: An input validation issue was addressed.
apple
CVE-2025-24174P3HIGHCVSS 7.7v14.7.32025-01-27
CVE-2025-24174 [HIGH] CVE-2025-24174: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24174
Component: CoreRoutine
Impact: An app may be able to determine a user’s current location
Description: The issue was addressed with improved checks.
apple
CVE-2025-24233P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24233 [CRITICAL] CVE-2025-24233: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24233
Component: AppleMobileFileIntegrity
Impact: A malicious app may be able to read or write to protected files
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24181P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24181 [CRITICAL] CVE-2025-24181: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24181
Component: Sandbox
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2026-20620P3HIGHCVSS 7.7v14.8.42026-02-11
CVE-2026-20620 [HIGH] CVE-2026-20620: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20620
Component: GPU Drivers
Impact: An attacker may be able to cause unexpected system termination or read kernel memory
Description: An out-of-bounds read issue was addressed with improved input validation.
apple
CVE-2025-24253P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24253 [CRITICAL] CVE-2025-24253: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24253
Component: StorageKit
Impact: An app may be able to access protected user data
Description: This issue was addressed with improved handling of symlinks.
apple
CVE-2025-24093P3CRITICALCVSS 9.8v14.7.32025-01-27
CVE-2025-24093 [CRITICAL] CVE-2025-24093: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24093
Component: Sandbox
Impact: An app may be able to access removable volumes without user consent
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43494P3HIGHCVSS 7.5v14.8.22025-11-03
CVE-2025-43494 [HIGH] CVE-2025-43494: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43494
Component: Mail
Impact: An attacker may be able to cause a persistent denial-of-service
Description: A mail header parsing issue was addressed with improved checks.
apple
CVE-2025-43193P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43193 [CRITICAL] CVE-2025-43193: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43193
Component: SecurityAgent
Impact: An app may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43184P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43184 [CRITICAL] CVE-2025-43184: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43184
Component: Shortcuts
Impact: A shortcut may be able to bypass sensitive Shortcuts app settings
Description: This issue was addressed by adding an additional prompt for user consent.
apple
CVE-2025-31247P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2025-31247 [HIGH] CVE-2025-31247: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31247
Component: SharedFileList
Impact: An attacker may gain access to protected parts of the file system
Description: A logic issue was addressed with improved state management.
apple
CVE-2025-43275P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43275 [CRITICAL] CVE-2025-43275: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43275
Component: NetAuth
Impact: An app may be able to break out of its sandbox
Description: A race condition was addressed with additional validation.
apple