Apple Macos Sonoma vulnerabilities

959 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
959
CISA KEV
11
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL73HIGH289MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 2 of 48
CVE-2025-46301MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46301 [MEDIUM] CVE-2025-46301: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46301 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20651MEDIUMCVSS 6.2v14.8.42026-02-11
CVE-2026-20651 [MEDIUM] CVE-2026-20651: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20651 Component: Messages Impact: An app may be able to access sensitive user data Description: A privacy issue was addressed with improved handling of temporary files.
apple
CVE-2026-20621MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20621 [MEDIUM] CVE-2026-20621: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20621 Component: Wi-Fi Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: The issue was addressed with improved memory handling.
apple
CVE-2025-46304MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46304 [MEDIUM] CVE-2025-46304: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46304 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-46302MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46302 [MEDIUM] CVE-2025-46302: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46302 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-46305MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46305 [MEDIUM] CVE-2025-46305: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46305 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20625MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20625 [MEDIUM] CVE-2026-20625: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20625 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2026-20653MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20653 [MEDIUM] CVE-2026-20653: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20653 Component: Shortcuts Impact: An app may be able to access sensitive user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-46303MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46303 [MEDIUM] CVE-2025-46303: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46303 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20634MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20634 [MEDIUM] CVE-2026-20634: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20634 Component: ImageIO Impact: Processing a maliciously crafted image may result in disclosure of process memory Description: The issue was addressed with improved memory handling.
apple
CVE-2025-46283MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-46283 [MEDIUM] CVE-2025-46283: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46283 Component: CoreServices Impact: An app may be able to access sensitive user data Description: A logic issue was addressed with improved validation.
apple
CVE-2026-20602MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20602 [MEDIUM] CVE-2026-20602: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20602 Component: WindowServer Impact: An app may be able to cause a denial-of-service Description: The issue was addressed with improved handling of caches.
apple
CVE-2026-20675MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20675 [MEDIUM] CVE-2026-20675: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20675 Component: ImageIO Impact: Processing a maliciously crafted image may lead to disclosure of user information Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-43417MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-43417 [MEDIUM] CVE-2025-43417: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-43417 Component: File Bookmark Impact: An app may be able to access user-sensitive data Description: A path handling issue was addressed with improved logic.
apple
CVE-2026-20673MEDIUMCVSS 5.3v14.8.42026-02-11
CVE-2026-20673 [MEDIUM] CVE-2026-20673: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20673 Component: Mail Impact: Turning off "Load remote content in messages” may not apply to all mail previews Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43403MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-43403 [MEDIUM] CVE-2025-43403: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-43403 Component: Compression Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management.
apple
CVE-2026-20612MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20612 [MEDIUM] CVE-2026-20612: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20612 Component: Spotlight Impact: An app may be able to access sensitive user data Description: A privacy issue was addressed with improved checks.
apple
CVE-2025-46300MEDIUMCVSS 5.7v14.8.42026-02-11
CVE-2025-46300 [MEDIUM] CVE-2025-46300: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46300 Component: Multi-Touch Impact: A malicious HID device may cause an unexpected process crash Description: The issue was addressed with improved bounds checks.
apple
CVE-2026-20680MEDIUMCVSS 6.5v14.8.42026-02-11
CVE-2026-20680 [MEDIUM] CVE-2026-20680: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20680 Component: Spotlight Impact: A sandboxed app may be able to access sensitive user data Description: The issue was addressed with additional restrictions on the observability of app states.
apple
CVE-2026-20624MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20624 [MEDIUM] CVE-2026-20624: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20624 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: An injection issue was addressed with improved validation.
apple