cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 21 of 48
CVE-2024-27850P4MEDIUMCVSS 6.5v14.52024-05-13
CVE-2024-27850 [MEDIUM] CVE-2024-27850: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27850 Component: WebKit Impact: A maliciously crafted webpage may be able to fingerprint the user Description: This issue was addressed with improvements to the noise injection algorithm.
apple
CVE-2024-27830P4MEDIUMCVSS 6.5v14.52024-05-13
CVE-2024-27830 [MEDIUM] CVE-2024-27830: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27830 Component: WebKit Canvas Impact: A maliciously crafted webpage may be able to fingerprint the user Description: This issue was addressed through improved state management.
apple
CVE-2024-27800P4MEDIUMCVSS 6.5v14.52024-05-13
CVE-2024-27800 [MEDIUM] CVE-2024-27800: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27800 Component: Messages Impact: Processing a maliciously crafted message may lead to a denial-of-service Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2023-40385P4MEDIUMCVSS 6.5v142023-09-26
CVE-2023-40385 [MEDIUM] CVE-2023-40385: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40385 Component: WebKit Impact: A remote attacker may be able to view leaked DNS queries with Private Relay turned on Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2024-54564P4MEDIUMCVSS 6.5v14.62024-07-29
CVE-2024-54564 [MEDIUM] CVE-2024-54564: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-54564 Component: AirDrop Impact: A file received from AirDrop may not have the quarantine flag applied Description: This issue was addressed through improved state management.
apple
CVE-2024-23218P4MEDIUMCVSS 5.9v14.32024-01-22
CVE-2024-23218 [MEDIUM] CVE-2024-23218: macOS Sonoma 14.3 Apple Security Update: About the security content of macOS Sonoma 14.3 Product: macOS Sonoma Version: 14.3 CVE: CVE-2024-23218 Component: CoreCrypto Impact: An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key Description: A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions.
apple
CVE-2024-44176P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-44176 [MEDIUM] CVE-2024-44176: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-44176 Component: ImageIO Impact: Processing an image may lead to a denial-of-service Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2024-44213P4MEDIUMCVSS 5.9v14.7.12024-10-28
CVE-2024-44213 [MEDIUM] CVE-2024-44213: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44213 Component: CUPS Impact: An attacker in a privileged network position may be able to leak sensitive user information Description: An issue existed in the parsing of URLs. This issue was addressed with improved input validation.
apple
CVE-2024-40777P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40777 [MEDIUM] CVE-2024-40777: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40777 Component: ImageIO Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2024-40799P4HIGHCVSS 7.1v14.62024-07-29
CVE-2024-40799 [HIGH] CVE-2024-40799: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40799 Component: CoreGraphics Impact: Processing a maliciously crafted file may lead to unexpected app termination Description: An out-of-bounds read issue was addressed with improved input validation.
apple
CVE-2020-19189P4MEDIUMCVSS 6.5v14.22023-12-11
CVE-2020-19189 [MEDIUM] CVE-2020-19189: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2020-19189 Component: CVE-2020-19189
apple
CVE-2023-3618P4MEDIUMCVSS 6.5v14.22023-12-11
CVE-2023-3618 [MEDIUM] CVE-2023-3618: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-3618 Component: CVE-2023-3618 Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution Description: This issue was addressed with improved checks.
apple
CVE-2024-54497P4MEDIUMCVSS 6.5v14.7.32025-01-27
CVE-2024-54497 [MEDIUM] CVE-2024-54497: macOS Sonoma 14.7.3 Apple Security Update: About the security content of macOS Sonoma 14.7.3 Product: macOS Sonoma Version: 14.7.3 CVE: CVE-2024-54497 Component: QuartzCore Impact: Processing web content may lead to a denial-of-service Description: The issue was addressed with improved checks.
apple
CVE-2024-23271P4MEDIUMCVSS 6.5v14.32024-01-22
CVE-2024-23271 [MEDIUM] CVE-2024-23271: macOS Sonoma 14.3 Apple Security Update: About the security content of macOS Sonoma 14.3 Product: macOS Sonoma Version: 14.3 CVE: CVE-2024-23271 Component: WebKit Impact: A malicious website may cause unexpected cross-origin behavior Description: A logic issue was addressed with improved checks.
apple
CVE-2024-43398P4MEDIUMCVSS 5.9v14.8.22025-11-03
CVE-2024-43398 [MEDIUM] CVE-2024-43398: macOS Sonoma 14.8.2 Apple Security Update: About the security content of macOS Sonoma 14.8.2 Product: macOS Sonoma Version: 14.8.2 CVE: CVE-2024-43398 Component: CVE-2024-43398
apple
CVE-2025-24157P4MEDIUMCVSS 5.6v14.7.52025-03-31
CVE-2025-24157 [MEDIUM] CVE-2025-24157: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24157 Component: Xsan Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2023-42898P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42898 [MEDIUM] CVE-2023-42898: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42898 Component: ImageIO Impact: Processing an image may lead to arbitrary code execution Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43247P4MEDIUMCVSS 5.5v14.7.72025-07-29
CVE-2025-43247 [MEDIUM] CVE-2025-43247: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43247 Component: PackageKit Impact: A malicious app with root privileges may be able to modify the contents of system files Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2024-40814P4HIGHCVSS 7.1v14.62024-07-29
CVE-2024-40814 [HIGH] CVE-2024-40814: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40814 Component: AppleMobileFileIntegrity Impact: An app may be able to bypass Privacy preferences Description: A downgrade issue was addressed with additional code-signing restrictions.
apple
CVE-2025-43338P4HIGHCVSS 7.1v14.8.22025-11-03
CVE-2025-43338 [HIGH] CVE-2025-43338: macOS Sonoma 14.8.2 Apple Security Update: About the security content of macOS Sonoma 14.8.2 Product: macOS Sonoma Version: 14.8.2 CVE: CVE-2025-43338 Component: ImageIO Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple