Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 23 of 48
CVE-2024-44141P4MEDIUMCVSS 6.8v14.62024-07-29
CVE-2024-44141 [MEDIUM] CVE-2024-44141: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-44141
Component: DiskArbitration
Impact: A person with physical access to an unlocked Mac may be able to gain root code execution
Description: The issue was addressed with improved checks.
apple
CVE-2023-42956P4MEDIUMCVSS 6.5v14.22023-12-11
CVE-2023-42956 [MEDIUM] CVE-2023-42956: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42956
Component: WebKit
Impact: Processing web content may lead to a denial-of-service
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-40441P4MEDIUMCVSS 6.5v142023-09-26
CVE-2023-40441 [MEDIUM] CVE-2023-40441: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40441
Component: GPU Drivers
Impact: Processing web content may lead to a denial-of-service
Description: A resource exhaustion issue was addressed with improved input validation.
apple
CVE-2024-54658P4MEDIUMCVSS 6.5v14.42024-03-07
CVE-2024-54658 [MEDIUM] CVE-2024-54658: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-54658
Component: WebKit
Impact: Processing web content may lead to a denial-of-service
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20680P4MEDIUMCVSS 6.5v14.8.42026-02-11
CVE-2026-20680 [MEDIUM] CVE-2026-20680: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20680
Component: Spotlight
Impact: A sandboxed app may be able to access sensitive user data
Description: The issue was addressed with additional restrictions on the observability of app states.
apple
CVE-2025-43448P4MEDIUMCVSS 6.3v14.8.22025-11-03
CVE-2025-43448 [MEDIUM] CVE-2025-43448: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43448
Component: CloudKit
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43412P4MEDIUMCVSS 6.3v14.8.22025-11-03
CVE-2025-43412 [MEDIUM] CVE-2025-43412: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43412
Component: TCC
Impact: An app may be able to break out of its sandbox
Description: A file quarantine bypass was addressed with additional checks.
apple
CVE-2025-40909P4MEDIUMCVSS 5.9v14.82025-09-15
CVE-2025-40909 [MEDIUM] CVE-2025-40909: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-40909
Component: CVE-2025-40909
apple
CVE-2024-44167P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-44167 [MEDIUM] CVE-2024-44167: macOS Sonoma 14.7
Apple Security Update: About the security content of macOS Sonoma 14.7
Product: macOS Sonoma
Version: 14.7
CVE: CVE-2024-44167
Component: Notes
Impact: An app may be able to overwrite arbitrary files
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-31241P4MEDIUMCVSS 5.3v14.7.62025-05-12
CVE-2025-31241 [MEDIUM] CVE-2025-31241: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31241
Component: Kernel
Impact: A remote attacker may cause an unexpected app termination
Description: A double free issue was addressed with improved memory management.
apple
CVE-2024-27791P4HIGHCVSS 7.1v14.32024-01-22
CVE-2024-27791 [HIGH] CVE-2024-27791: macOS Sonoma 14.3
Apple Security Update: About the security content of macOS Sonoma 14.3
Product: macOS Sonoma
Version: 14.3
CVE: CVE-2024-27791
Component: Power Manager
Impact: An app may be able to corrupt coprocessor memory
Description: The issue was addressed with improved checks.
apple
CVE-2023-41988P4MEDIUMCVSS 6.8v14.12023-10-25
CVE-2023-41988 [MEDIUM] CVE-2023-41988: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41988
Component: Siri
Impact: An attacker with physical access may be able to use Siri to access sensitive user data
Description: This issue was addressed by restricting options offered on a locked device.
apple
CVE-2023-42914P4MEDIUMCVSS 6.3v14.22023-12-11
CVE-2023-42914 [MEDIUM] CVE-2023-42914: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42914
Component: Kernel
Impact: An app may be able to break out of its sandbox
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-24212P4MEDIUMCVSS 6.3v14.7.52025-03-31
CVE-2025-24212 [MEDIUM] CVE-2025-24212: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24212
Component: Calendar
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved checks.
apple
CVE-2025-30429P4MEDIUMCVSS 6.3v14.7.52025-03-31
CVE-2025-30429 [MEDIUM] CVE-2025-30429: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30429
Component: Calendar
Impact: An app may be able to break out of its sandbox
Description: A path handling issue was addressed with improved validation.
apple
CVE-2023-42887P4MEDIUMCVSS 6.3v14.22023-12-11
CVE-2023-42887 [MEDIUM] CVE-2023-42887: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42887
Component: NSOpenPanel
Impact: An app may be able to read arbitrary files
Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2024-40817P4MEDIUMCVSS 6.1v14.62024-07-29
CVE-2024-40817 [MEDIUM] CVE-2024-40817: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40817
Component: Safari
Impact: Visiting a website that frames malicious content may lead to UI spoofing
Description: The issue was addressed with improved UI handling.
apple
CVE-2024-40797P4MEDIUMCVSS 6.1v14.72024-09-16
CVE-2024-40797 [MEDIUM] CVE-2024-40797: macOS Sonoma 14.7
Apple Security Update: About the security content of macOS Sonoma 14.7
Product: macOS Sonoma
Version: 14.7
CVE: CVE-2024-40797
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: This issue was addressed through improved state management.
apple
CVE-2026-20651P4MEDIUMCVSS 6.2v14.8.42026-02-11
CVE-2026-20651 [MEDIUM] CVE-2026-20651: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20651
Component: Messages
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved handling of temporary files.
apple
CVE-2025-43414P4MEDIUMCVSS 6.2v14.8.22025-11-03
CVE-2025-43414 [MEDIUM] CVE-2025-43414: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43414
Component: Shortcuts
Impact: A shortcut may be able to access files that are normally inaccessible to the Shortcuts app
Description: A permissions issue was addressed with improved validation.
apple