Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 20 of 48
CVE-2025-24131P4MEDIUMCVSS 6.5v14.7.52025-03-31
CVE-2025-24131 [MEDIUM] CVE-2025-24131: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24131
Component: AirPlay
Impact: An attacker on the local network may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-40420P4MEDIUMCVSS 6.5v142023-09-26
CVE-2023-40420 [MEDIUM] CVE-2023-40420: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40420
Component: CoreAnimation
Impact: Processing web content may lead to a denial-of-service
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-40403P4MEDIUMCVSS 6.5v142023-09-26
CVE-2023-40403 [MEDIUM] CVE-2023-40403: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40403
Component: LaunchServices
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-40782P4MEDIUMCVSS 6.5v14.62024-07-29
CVE-2024-40782 [MEDIUM] CVE-2024-40782: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40782
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2024-27878P4MEDIUMCVSS 6.7v14.62024-07-29
CVE-2024-27878 [MEDIUM] CVE-2024-27878: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27878
Component: ASP TCP
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2024-27838P4MEDIUMCVSS 6.5v14.52024-05-13
CVE-2024-27838 [MEDIUM] CVE-2024-27838: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27838
Component: WebKit
Impact: A maliciously crafted webpage may be able to fingerprint the user
Description: The issue was addressed by adding additional logic.
apple
CVE-2025-43538P4MEDIUMCVSS 5.5v14.8.32025-12-12
CVE-2025-43538 [MEDIUM] CVE-2025-43538: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-43538
Component: Screen Time
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
apple
CVE-2023-42982P4MEDIUMCVSS 6.4v142023-09-26
CVE-2023-42982 [MEDIUM] CVE-2023-42982: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42982
Component: Model I/O
Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents
Description: The issue was addressed with improved checks.
apple
CVE-2023-42983P4MEDIUMCVSS 6.4v142023-09-26
CVE-2023-42983 [MEDIUM] CVE-2023-42983: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42983
Component: Model I/O
Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents
Description: The issue was addressed with improved checks.
apple
CVE-2024-27823P4MEDIUMCVSS 5.9v14.52024-05-13
CVE-2024-27823 [MEDIUM] CVE-2024-27823: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27823
Component: Kernel
Impact: An attacker in a privileged network position may be able to spoof network packets
Description: A race condition was addressed with improved locking.
apple
CVE-2025-24118P4HIGHCVSS 7.1v14.7.32025-01-27
CVE-2025-24118 [HIGH] CVE-2025-24118: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24118
Component: Kernel
Impact: An app may be able to cause unexpected system termination or write kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-44236P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44236 [MEDIUM] CVE-2024-44236: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44236
Component: Shortcuts
Impact: A malicious app may use shortcuts to access restricted files
Description: A logic issue was addressed with improved checks.
apple
CVE-2023-40452P4HIGHCVSS 7.1v142023-09-26
CVE-2023-40452 [HIGH] CVE-2023-40452: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40452
Component: Sandbox
Impact: An app may be able to overwrite arbitrary files
Description: The issue was addressed with improved bounds checks.
apple
CVE-2023-6277P4MEDIUMCVSS 6.5v14.62024-07-29
CVE-2023-6277 [MEDIUM] CVE-2023-6277: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2023-6277
Component: CVE-2023-6277
apple
CVE-2024-23216P4HIGHCVSS 7.1v14.42024-03-07
CVE-2024-23216 [HIGH] CVE-2024-23216: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23216
Component: PackageKit
Impact: An app may be able to overwrite arbitrary files
Description: A path handling issue was addressed with improved validation.
apple
CVE-2026-20606P4HIGHCVSS 7.1v14.8.42026-02-11
CVE-2026-20606 [HIGH] CVE-2026-20606: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20606
Component: UIKit
Impact: An app may be able to bypass certain Privacy preferences
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2023-41983P4MEDIUMCVSS 6.5v14.12023-10-25
CVE-2023-41983 [MEDIUM] CVE-2023-41983: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41983
Component: WebKit Process Model
Impact: Processing web content may lead to a denial-of-service
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-41989P4MEDIUMCVSS 6.8v14.12023-10-25
CVE-2023-41989 [MEDIUM] CVE-2023-41989: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41989
Component: Emoji
Impact: An attacker may be able to execute arbitrary code as root from the Lock Screen
Description: The issue was addressed by restricting options offered on a locked device.
apple
CVE-2024-2379P4MEDIUMCVSS 6.3v14.62024-07-29
CVE-2024-2379 [MEDIUM] CVE-2024-2379: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-2379
Component: CVE-2024-2379
apple
CVE-2024-44297P4MEDIUMCVSS 6.5v14.7.12024-10-28
CVE-2024-44297 [MEDIUM] CVE-2024-44297: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44297
Component: ImageIO
Impact: Processing a maliciously crafted message may lead to a denial-of-service
Description: The issue was addressed with improved bounds checks.
apple