Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 15 of 48
CVE-2024-23294P3HIGHCVSS 7.8v14.42024-03-07
CVE-2024-23294 [HIGH] CVE-2024-23294: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23294
Component: QuartzCore
Impact: Processing malicious input may lead to code execution
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2024-44126P3HIGHCVSS 7.8v14.72024-09-16
CVE-2024-44126 [HIGH] CVE-2024-44126: macOS Sonoma 14.7
Apple Security Update: About the security content of macOS Sonoma 14.7
Product: macOS Sonoma
Version: 14.7
CVE: CVE-2024-44126
Component: ARKit
Impact: Processing a maliciously crafted file may lead to heap corruption
Description: The issue was addressed with improved checks.
apple
CVE-2025-24170P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24170 [HIGH] CVE-2025-24170: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24170
Component: CoreServices
Impact: An app may be able to gain root privileges
Description: A logic issue was addressed with improved file handling.
apple
CVE-2023-42826P3HIGHCVSS 7.8v142023-09-26
CVE-2023-42826 [HIGH] CVE-2023-42826: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42826
Component: Model I/O
Impact: Processing a file may lead to arbitrary code execution
Description: The issue was addressed with improved checks.
apple
CVE-2024-27824P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27824 [HIGH] CVE-2024-27824: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27824
Component: PackageKit
Impact: An app may be able to elevate privileges
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2023-42881P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42881 [HIGH] CVE-2023-42881: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42881
Component: AppleVA
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43248P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-43248 [HIGH] CVE-2025-43248: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43248
Component: AppleMobileFileIntegrity
Impact: A malicious app may be able to gain root privileges
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2025-31243P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-31243 [HIGH] CVE-2025-31243: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-31243
Component: AppleMobileFileIntegrity
Impact: An app may be able to gain root privileges
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42848P3HIGHCVSS 7.8v14.12023-10-25
CVE-2023-42848 [HIGH] CVE-2023-42848: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42848
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to heap corruption
Description: The issue was addressed with improved bounds checks.
apple
CVE-2024-27798P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27798 [HIGH] CVE-2024-27798: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27798
Component: StorageKit
Impact: An attacker may be able to elevate privileges
Description: An authorization issue was addressed with improved state management.
apple
CVE-2024-54538P3HIGHCVSS 7.5v14.7.12024-10-28
CVE-2024-54538 [HIGH] CVE-2024-54538: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-54538
Component: Security
Impact: A remote attacker may be able to cause a denial-of-service
Description: A denial-of-service issue was addressed with improved input validation.
apple
CVE-2025-30457P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30457 [CRITICAL] CVE-2025-30457: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30457
Component: SystemMigration
Impact: A malicious app may be able to create symlinks to protected regions of the disk
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-24231P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24231 [CRITICAL] CVE-2025-24231: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24231
Component: AppleMobileFileIntegrity
Impact: An app may be able to modify protected parts of the file system
Description: The issue was addressed with improved checks.
apple
CVE-2025-24207P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24207 [CRITICAL] CVE-2025-24207: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24207
Component: Storage Management
Impact: An app may be able to enable iCloud storage features without user consent
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-31279P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-31279 [CRITICAL] CVE-2025-31279: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-31279
Component: Find My
Impact: An app may be able to fingerprint the user
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24247P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24247 [CRITICAL] CVE-2025-24247: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24247
Component: WindowServer
Impact: An attacker may be able to cause unexpected app termination
Description: A type confusion issue was addressed with improved checks.
apple
CVE-2024-44289P3HIGHCVSS 7.5v14.7.12024-10-28
CVE-2024-44289 [HIGH] CVE-2024-44289: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44289
Component: Find My
Impact: An app may be able to read sensitive location information
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-31240P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2025-31240 [HIGH] CVE-2025-31240: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31240
Component: About Apple security updates
Impact: Connecting to a malicious AFP server may corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-31237P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2025-31237 [HIGH] CVE-2025-31237: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31237
Component: About Apple security updates
Impact: Connecting to a malicious AFP server may corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43194P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43194 [CRITICAL] CVE-2025-43194: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43194
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: The issue was addressed with improved checks.
apple