cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 24 of 48
CVE-2025-46310P4MEDIUMCVSS 6.0v14.8.42026-02-11
CVE-2025-46310 [MEDIUM] CVE-2025-46310: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46310 Component: PackageKit Impact: An attacker with root privileges may be able to delete protected system files Description: This issue was addressed through improved state management.
apple
CVE-2024-40794P4MEDIUMCVSS 5.3v14.62024-07-29
CVE-2024-40794 [MEDIUM] CVE-2024-40794: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40794 Component: WebKit Impact: Private Browsing tabs may be accessed without authentication Description: This issue was addressed through improved state management.
apple
CVE-2023-41968P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-41968 [MEDIUM] CVE-2023-41968: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-41968 Component: StorageKit Impact: An app may be able to read arbitrary files Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2024-40827P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40827 [MEDIUM] CVE-2024-40827: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40827 Component: DesktopServices Impact: An app may be able to overwrite arbitrary files Description: The issue was addressed with improved checks.
apple
CVE-2023-42845P4MEDIUMCVSS 5.3v14.12023-10-25
CVE-2023-42845 [MEDIUM] CVE-2023-42845: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42845 Component: Photos Impact: Photos in the Hidden Photos Album may be viewed without authentication Description: An authentication issue was addressed with improved state management.
apple
CVE-2024-44190P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-44190 [MEDIUM] CVE-2024-44190: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-44190 Component: System Settings Impact: An app may be able to read arbitrary files Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-43308P4MEDIUMCVSS 5.3v14.82025-09-15
CVE-2025-43308 [MEDIUM] CVE-2025-43308: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43308 Component: Touch Bar Controls Impact: An app may be able to access sensitive user data Description: This issue was addressed with additional entitlement checks.
apple
CVE-2026-20673P4MEDIUMCVSS 5.3v14.8.42026-02-11
CVE-2026-20673 [MEDIUM] CVE-2026-20673: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20673 Component: Mail Impact: Turning off "Load remote content in messages” may not apply to all mail previews Description: A logic issue was addressed with improved checks.
apple
CVE-2024-23248P4HIGHCVSS 7.1v14.42024-03-07
CVE-2024-23248 [HIGH] CVE-2024-23248: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-23248 Component: ColorSync Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents Description: The issue was addressed with improved memory handling.
apple
CVE-2024-23249P4HIGHCVSS 7.1v14.42024-03-07
CVE-2024-23249 [HIGH] CVE-2024-23249: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-23249 Component: ColorSync Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents Description: The issue was addressed with improved memory handling.
apple
CVE-2023-38610P4HIGHCVSS 7.1v142023-09-26
CVE-2023-38610 [HIGH] CVE-2023-38610: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-38610 Component: Wi-Fi Impact: An app may be able to cause unexpected system termination or write kernel memory Description: A memory corruption issue was addressed by removing the vulnerable code.
apple
CVE-2023-42876P4HIGHCVSS 7.1v142023-09-26
CVE-2023-42876 [HIGH] CVE-2023-42876: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-42876 Component: BOM Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-5918P4LOWCVSS 3.9v14.8.32025-12-12
CVE-2025-5918 [LOW] CVE-2025-5918: macOS Sonoma 14.8.3 Apple Security Update: About the security content of macOS Sonoma 14.8.3 Product: macOS Sonoma Version: 14.8.3 CVE: CVE-2025-5918 Component: CVE-2025-5918
apple
CVE-2024-23223P4MEDIUMCVSS 6.2v14.32024-01-22
CVE-2024-23223 [MEDIUM] CVE-2024-23223: macOS Sonoma 14.3 Apple Security Update: About the security content of macOS Sonoma 14.3 Product: macOS Sonoma Version: 14.3 CVE: CVE-2024-23223 Component: NSSpellChecker Impact: An app may be able to access sensitive user data Description: A privacy issue was addressed with improved handling of files.
apple
CVE-2025-24270P4MEDIUMCVSS 5.7v14.7.52025-03-31
CVE-2025-24270 [MEDIUM] CVE-2025-24270: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24270 Component: AirPlay Impact: An attacker on the local network may be able to leak sensitive user information Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2023-40408P4MEDIUMCVSS 5.3v14.12023-10-25
CVE-2023-40408 [MEDIUM] CVE-2023-40408: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-40408 Component: Mail Drafts Impact: Hide My Email may be deactivated unexpectedly Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2023-42888P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42888 [MEDIUM] CVE-2023-42888: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42888 Component: ImageIO Impact: Processing a maliciously crafted image may result in disclosure of process memory Description: The issue was addressed with improved checks.
apple
CVE-2024-40796P4MEDIUMCVSS 5.3v14.62024-07-29
CVE-2024-40796 [MEDIUM] CVE-2024-40796: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40796 Component: NetworkExtension Impact: Private browsing may leak some browsing history Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-43416P4MEDIUMCVSS 5.5v14.8.32025-12-12
CVE-2025-43416 [MEDIUM] CVE-2025-43416: macOS Sonoma 14.8.3 Apple Security Update: About the security content of macOS Sonoma 14.8.3 Product: macOS Sonoma Version: 14.8.3 CVE: CVE-2025-43416 Component: StorageKit Impact: An app may be able to access sensitive user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2024-27881P4MEDIUMCVSS 5.3v14.62024-07-29
CVE-2024-27881 [MEDIUM] CVE-2024-27881: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-27881 Component: Scripting Bridge Impact: An app may be able to access information about a user’s contacts Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
Apple Macos Sonoma vulnerabilities | cvebase