Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 24 of 48
CVE-2025-46310P4MEDIUMCVSS 6.0v14.8.42026-02-11
CVE-2025-46310 [MEDIUM] CVE-2025-46310: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46310
Component: PackageKit
Impact: An attacker with root privileges may be able to delete protected system files
Description: This issue was addressed through improved state management.
apple
CVE-2024-40794P4MEDIUMCVSS 5.3v14.62024-07-29
CVE-2024-40794 [MEDIUM] CVE-2024-40794: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40794
Component: WebKit
Impact: Private Browsing tabs may be accessed without authentication
Description: This issue was addressed through improved state management.
apple
CVE-2023-41968P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-41968 [MEDIUM] CVE-2023-41968: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-41968
Component: StorageKit
Impact: An app may be able to read arbitrary files
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2024-40827P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40827 [MEDIUM] CVE-2024-40827: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40827
Component: DesktopServices
Impact: An app may be able to overwrite arbitrary files
Description: The issue was addressed with improved checks.
apple
CVE-2023-42845P4MEDIUMCVSS 5.3v14.12023-10-25
CVE-2023-42845 [MEDIUM] CVE-2023-42845: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42845
Component: Photos
Impact: Photos in the Hidden Photos Album may be viewed without authentication
Description: An authentication issue was addressed with improved state management.
apple
CVE-2024-44190P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-44190 [MEDIUM] CVE-2024-44190: macOS Sonoma 14.7
Apple Security Update: About the security content of macOS Sonoma 14.7
Product: macOS Sonoma
Version: 14.7
CVE: CVE-2024-44190
Component: System Settings
Impact: An app may be able to read arbitrary files
Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-43308P4MEDIUMCVSS 5.3v14.82025-09-15
CVE-2025-43308 [MEDIUM] CVE-2025-43308: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43308
Component: Touch Bar Controls
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2026-20673P4MEDIUMCVSS 5.3v14.8.42026-02-11
CVE-2026-20673 [MEDIUM] CVE-2026-20673: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20673
Component: Mail
Impact: Turning off "Load remote content in messages” may not apply to all mail previews
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-23248P4HIGHCVSS 7.1v14.42024-03-07
CVE-2024-23248 [HIGH] CVE-2024-23248: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23248
Component: ColorSync
Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-23249P4HIGHCVSS 7.1v14.42024-03-07
CVE-2024-23249 [HIGH] CVE-2024-23249: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23249
Component: ColorSync
Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-38610P4HIGHCVSS 7.1v142023-09-26
CVE-2023-38610 [HIGH] CVE-2023-38610: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-38610
Component: Wi-Fi
Impact: An app may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed by removing the vulnerable code.
apple
CVE-2023-42876P4HIGHCVSS 7.1v142023-09-26
CVE-2023-42876 [HIGH] CVE-2023-42876: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42876
Component: BOM
Impact: Processing a file may lead to a denial-of-service or potentially disclose memory contents
Description: The issue was addressed with improved bounds checks.
apple
CVE-2025-5918P4LOWCVSS 3.9v14.8.32025-12-12
CVE-2025-5918 [LOW] CVE-2025-5918: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-5918
Component: CVE-2025-5918
apple
CVE-2024-23223P4MEDIUMCVSS 6.2v14.32024-01-22
CVE-2024-23223 [MEDIUM] CVE-2024-23223: macOS Sonoma 14.3
Apple Security Update: About the security content of macOS Sonoma 14.3
Product: macOS Sonoma
Version: 14.3
CVE: CVE-2024-23223
Component: NSSpellChecker
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved handling of files.
apple
CVE-2025-24270P4MEDIUMCVSS 5.7v14.7.52025-03-31
CVE-2025-24270 [MEDIUM] CVE-2025-24270: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24270
Component: AirPlay
Impact: An attacker on the local network may be able to leak sensitive user information
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2023-40408P4MEDIUMCVSS 5.3v14.12023-10-25
CVE-2023-40408 [MEDIUM] CVE-2023-40408: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-40408
Component: Mail Drafts
Impact: Hide My Email may be deactivated unexpectedly
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2023-42888P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42888 [MEDIUM] CVE-2023-42888: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42888
Component: ImageIO
Impact: Processing a maliciously crafted image may result in disclosure of process memory
Description: The issue was addressed with improved checks.
apple
CVE-2024-40796P4MEDIUMCVSS 5.3v14.62024-07-29
CVE-2024-40796 [MEDIUM] CVE-2024-40796: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40796
Component: NetworkExtension
Impact: Private browsing may leak some browsing history
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-43416P4MEDIUMCVSS 5.5v14.8.32025-12-12
CVE-2025-43416 [MEDIUM] CVE-2025-43416: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-43416
Component: StorageKit
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2024-27881P4MEDIUMCVSS 5.3v14.62024-07-29
CVE-2024-27881 [MEDIUM] CVE-2024-27881: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27881
Component: Scripting Bridge
Impact: An app may be able to access information about a user’s contacts
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple