cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 15 of 48
CVE-2024-23294P3HIGHCVSS 7.8v14.42024-03-07
CVE-2024-23294 [HIGH] CVE-2024-23294: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-23294 Component: QuartzCore Impact: Processing malicious input may lead to code execution Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2024-44126P3HIGHCVSS 7.8v14.72024-09-16
CVE-2024-44126 [HIGH] CVE-2024-44126: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-44126 Component: ARKit Impact: Processing a maliciously crafted file may lead to heap corruption Description: The issue was addressed with improved checks.
apple
CVE-2025-24170P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24170 [HIGH] CVE-2025-24170: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24170 Component: CoreServices Impact: An app may be able to gain root privileges Description: A logic issue was addressed with improved file handling.
apple
CVE-2023-42826P3HIGHCVSS 7.8v142023-09-26
CVE-2023-42826 [HIGH] CVE-2023-42826: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-42826 Component: Model I/O Impact: Processing a file may lead to arbitrary code execution Description: The issue was addressed with improved checks.
apple
CVE-2024-27824P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27824 [HIGH] CVE-2024-27824: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27824 Component: PackageKit Impact: An app may be able to elevate privileges Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2023-42881P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42881 [HIGH] CVE-2023-42881: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42881 Component: AppleVA Impact: Processing a file may lead to unexpected app termination or arbitrary code execution Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43248P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-43248 [HIGH] CVE-2025-43248: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43248 Component: AppleMobileFileIntegrity Impact: A malicious app may be able to gain root privileges Description: A logic issue was addressed with improved restrictions.
apple
CVE-2025-31243P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-31243 [HIGH] CVE-2025-31243: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-31243 Component: AppleMobileFileIntegrity Impact: An app may be able to gain root privileges Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42848P3HIGHCVSS 7.8v14.12023-10-25
CVE-2023-42848 [HIGH] CVE-2023-42848: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42848 Component: ImageIO Impact: Processing a maliciously crafted image may lead to heap corruption Description: The issue was addressed with improved bounds checks.
apple
CVE-2024-27798P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27798 [HIGH] CVE-2024-27798: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27798 Component: StorageKit Impact: An attacker may be able to elevate privileges Description: An authorization issue was addressed with improved state management.
apple
CVE-2024-54538P3HIGHCVSS 7.5v14.7.12024-10-28
CVE-2024-54538 [HIGH] CVE-2024-54538: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-54538 Component: Security Impact: A remote attacker may be able to cause a denial-of-service Description: A denial-of-service issue was addressed with improved input validation.
apple
CVE-2025-30457P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30457 [CRITICAL] CVE-2025-30457: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-30457 Component: SystemMigration Impact: A malicious app may be able to create symlinks to protected regions of the disk Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-24231P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24231 [CRITICAL] CVE-2025-24231: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24231 Component: AppleMobileFileIntegrity Impact: An app may be able to modify protected parts of the file system Description: The issue was addressed with improved checks.
apple
CVE-2025-24207P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24207 [CRITICAL] CVE-2025-24207: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24207 Component: Storage Management Impact: An app may be able to enable iCloud storage features without user consent Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-31279P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-31279 [CRITICAL] CVE-2025-31279: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-31279 Component: Find My Impact: An app may be able to fingerprint the user Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24247P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24247 [CRITICAL] CVE-2025-24247: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24247 Component: WindowServer Impact: An attacker may be able to cause unexpected app termination Description: A type confusion issue was addressed with improved checks.
apple
CVE-2024-44289P3HIGHCVSS 7.5v14.7.12024-10-28
CVE-2024-44289 [HIGH] CVE-2024-44289: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44289 Component: Find My Impact: An app may be able to read sensitive location information Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-31240P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2025-31240 [HIGH] CVE-2025-31240: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-31240 Component: About Apple security updates Impact: Connecting to a malicious AFP server may corrupt kernel memory Description: The issue was addressed with improved memory handling.
apple
CVE-2025-31237P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2025-31237 [HIGH] CVE-2025-31237: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-31237 Component: About Apple security updates Impact: Connecting to a malicious AFP server may corrupt kernel memory Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43194P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43194 [CRITICAL] CVE-2025-43194: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43194 Component: PackageKit Impact: An app may be able to modify protected parts of the file system Description: The issue was addressed with improved checks.
apple
Apple Macos Sonoma vulnerabilities | cvebase