Apple Macos Sonoma vulnerabilities
959 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
959
CISA KEV
11
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL73HIGH289MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 17 of 48
CVE-2025-24205MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24205 [MEDIUM] CVE-2025-24205: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24205
Component: Siri
Impact: An app may be able to access user-sensitive data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-43205MEDIUMCVSS 4.0v14.7.52025-03-31
CVE-2025-43205 [MEDIUM] CVE-2025-43205: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-43205
Component: Audio
Impact: An app may be able to bypass ASLR
Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2025-30450MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30450 [MEDIUM] CVE-2025-30450: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30450
Component: Mail
Impact: "Block All Remote Content" may not apply for all mail previews
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2025-30447MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30447 [MEDIUM] CVE-2025-30447: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30447
Component: Foundation
Impact: An app may be able to access sensitive user data
Description: The issue was resolved by sanitizing logging
apple
CVE-2025-30454MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30454 [MEDIUM] CVE-2025-30454: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30454
Component: CoreMedia Playback
Impact: A malicious app may be able to access private information
Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-31203MEDIUMCVSS 6.5v14.7.52025-03-31
CVE-2025-31203 [MEDIUM] CVE-2025-31203: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31203
Component: CoreUtils
Impact: An attacker on the local network may be able to cause a denial-of-service
Description: An integer overflow was addressed with improved input validation.
apple
CVE-2025-31191MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-31191 [MEDIUM] CVE-2025-31191: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31191
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: This issue was addressed through improved state management.
apple
CVE-2025-24280MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24280 [MEDIUM] CVE-2025-24280: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24280
Component: Shortcuts
Impact: An app may be able to access user-sensitive data
Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2025-24244MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24244 [MEDIUM] CVE-2025-24244: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24244
Component: Audio
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-24279MEDIUMCVSS 4.3v14.7.52025-03-31
CVE-2025-24279 [MEDIUM] CVE-2025-24279: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24279
Component: Voice Control
Impact: An app may be able to access contacts
Description: This issue was addressed with improved file handling.
apple
CVE-2025-24111MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24111 [MEDIUM] CVE-2025-24111: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24111
Component: Display
Impact: An app may be able to cause unexpected system termination
Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2025-30455MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30455 [MEDIUM] CVE-2025-30455: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30455
Component: Dock
Impact: A malicious app may be able to access private information
Description: The issue was addressed with improved checks.
apple
CVE-2025-24097MEDIUMCVSS 5.0v14.7.52025-03-31
CVE-2025-24097 [MEDIUM] CVE-2025-24097: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24097
Component: AirDrop
Impact: An app may be able to read arbitrary file metadata
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24276MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24276 [MEDIUM] CVE-2025-24276: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24276
Component: App Store
Impact: A malicious app may be able to access private information
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-30432MEDIUMCVSS 6.4v14.7.52025-03-31
CVE-2025-30432 [MEDIUM] CVE-2025-30432: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30432
Component: Kernel
Impact: A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures
Description: A logic issue was addressed with improved state management.
apple
CVE-2025-31261MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-31261 [MEDIUM] CVE-2025-31261: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31261
Component: StorageKit
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2025-24240MEDIUMCVSS 4.7v14.7.52025-03-31
CVE-2025-24240 [MEDIUM] CVE-2025-24240: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24240
Component: StorageKit
Impact: An app may be able to access user-sensitive data
Description: A race condition was addressed with additional validation.
apple
CVE-2025-24212MEDIUMCVSS 6.3v14.7.52025-03-31
CVE-2025-24212 [MEDIUM] CVE-2025-24212: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24212
Component: Calendar
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved checks.
apple
CVE-2025-30438MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30438 [MEDIUM] CVE-2025-30438: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30438
Component: Share Sheet
Impact: A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started
Description: This issue was addressed with improved access restrictions.
apple
CVE-2025-31197MEDIUMCVSS 5.7v14.7.52025-03-31
CVE-2025-31197 [MEDIUM] CVE-2025-31197: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31197
Component: AirPlay
Impact: An attacker on the local network may cause an unexpected app termination
Description: The issue was addressed with improved checks.
apple