Apple Macos Sonoma vulnerabilities
959 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
959
CISA KEV
11
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL73HIGH289MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 2 of 48
CVE-2025-46301MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46301 [MEDIUM] CVE-2025-46301: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46301
Component: Multi-Touch
Impact: A malicious HID device may cause an unexpected process crash
Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20651MEDIUMCVSS 6.2v14.8.42026-02-11
CVE-2026-20651 [MEDIUM] CVE-2026-20651: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20651
Component: Messages
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved handling of temporary files.
apple
CVE-2026-20621MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20621 [MEDIUM] CVE-2026-20621: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20621
Component: Wi-Fi
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-46304MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46304 [MEDIUM] CVE-2025-46304: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46304
Component: Multi-Touch
Impact: A malicious HID device may cause an unexpected process crash
Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-46302MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46302 [MEDIUM] CVE-2025-46302: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46302
Component: Multi-Touch
Impact: A malicious HID device may cause an unexpected process crash
Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-46305MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46305 [MEDIUM] CVE-2025-46305: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46305
Component: Multi-Touch
Impact: A malicious HID device may cause an unexpected process crash
Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20625MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20625 [MEDIUM] CVE-2026-20625: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20625
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2026-20653MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20653 [MEDIUM] CVE-2026-20653: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20653
Component: Shortcuts
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-46303MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46303 [MEDIUM] CVE-2025-46303: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46303
Component: Multi-Touch
Impact: A malicious HID device may cause an unexpected process crash
Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20634MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20634 [MEDIUM] CVE-2026-20634: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20634
Component: ImageIO
Impact: Processing a maliciously crafted image may result in disclosure of process memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-46283MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-46283 [MEDIUM] CVE-2025-46283: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46283
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
apple
CVE-2026-20602MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20602 [MEDIUM] CVE-2026-20602: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20602
Component: WindowServer
Impact: An app may be able to cause a denial-of-service
Description: The issue was addressed with improved handling of caches.
apple
CVE-2026-20675MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20675 [MEDIUM] CVE-2026-20675: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20675
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to disclosure of user information
Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-43417MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-43417 [MEDIUM] CVE-2025-43417: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-43417
Component: File Bookmark
Impact: An app may be able to access user-sensitive data
Description: A path handling issue was addressed with improved logic.
apple
CVE-2026-20673MEDIUMCVSS 5.3v14.8.42026-02-11
CVE-2026-20673 [MEDIUM] CVE-2026-20673: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20673
Component: Mail
Impact: Turning off "Load remote content in messages” may not apply to all mail previews
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43403MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-43403 [MEDIUM] CVE-2025-43403: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-43403
Component: Compression
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2026-20612MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20612 [MEDIUM] CVE-2026-20612: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20612
Component: Spotlight
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved checks.
apple
CVE-2025-46300MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46300 [MEDIUM] CVE-2025-46300: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46300
Component: Multi-Touch
Impact: A malicious HID device may cause an unexpected process crash
Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20680MEDIUMCVSS 6.5v14.8.42026-02-11
CVE-2026-20680 [MEDIUM] CVE-2026-20680: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20680
Component: Spotlight
Impact: A sandboxed app may be able to access sensitive user data
Description: The issue was addressed with additional restrictions on the observability of app states.
apple
CVE-2026-20624MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20624 [MEDIUM] CVE-2026-20624: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20624
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: An injection issue was addressed with improved validation.
apple