Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 26 of 48
CVE-2023-42940P4MEDIUMCVSS 5.7v14.2.12023-12-19
CVE-2023-42940 [MEDIUM] CVE-2023-42940: macOS Sonoma 14.2.1
Apple Security Update: About the security content of macOS Sonoma 14.2.1
Product: macOS Sonoma
Version: 14.2.1
CVE: CVE-2023-42940
Component: WindowServer
Impact: A user who shares their screen may unintentionally share the incorrect content
Description: A session rendering issue was addressed with improved session tracking.
apple
CVE-2024-44282P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44282 [MEDIUM] CVE-2024-44282: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44282
Component: Foundation
Impact: Parsing a file may lead to disclosure of user information
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2024-23264P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-23264 [MEDIUM] CVE-2024-23264: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23264
Component: Metal
Impact: An application may be able to read restricted memory
Description: A validation issue was addressed with improved input sanitization.
apple
CVE-2024-23287P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-23287 [MEDIUM] CVE-2024-23287: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23287
Component: Messages
Impact: An app may be able to access user-sensitive data
Description: A privacy issue was addressed with improved handling of temporary files.
apple
CVE-2024-44175P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44175 [MEDIUM] CVE-2024-44175: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44175
Component: Kernel
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2023-40417P4MEDIUMCVSS 5.4v142023-09-26
CVE-2023-40417 [MEDIUM] CVE-2023-40417: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40417
Component: Safari
Impact: Visiting a website that frames malicious content may lead to UI spoofing
Description: A window management issue was addressed with improved state management.
apple
CVE-2024-44240P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44240 [MEDIUM] CVE-2024-44240: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44240
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: The issue was addressed with improved checks.
apple
CVE-2024-44302P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44302 [MEDIUM] CVE-2024-44302: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44302
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: The issue was addressed with improved checks.
apple
CVE-2024-23290P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-23290 [MEDIUM] CVE-2024-23290: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23290
Component: Sandbox
Impact: An app may be able to access user-sensitive data
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2023-40413P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-40413 [MEDIUM] CVE-2023-40413: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-40413
Component: Find My
Impact: An app may be able to read sensitive location information
Description: The issue was addressed with improved handling of caches.
apple
CVE-2023-42919P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42919 [MEDIUM] CVE-2023-42919: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42919
Component: Accounts
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-41254P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-41254 [MEDIUM] CVE-2023-41254: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41254
Component: Weather
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-41073P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-41073 [MEDIUM] CVE-2023-41073: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-41073
Component: LaunchServices
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-24149P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-24149 [MEDIUM] CVE-2025-24149: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24149
Component: SceneKit
Impact: Parsing a file may lead to disclosure of user information
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2025-24244P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24244 [MEDIUM] CVE-2025-24244: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24244
Component: Audio
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-42937P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42937 [MEDIUM] CVE-2023-42937: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42937
Component: Accessibility
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-24210P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24210 [MEDIUM] CVE-2025-24210: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24210
Component: ImageIO
Impact: Parsing an image may lead to disclosure of user information
Description: A logic error was addressed with improved error handling.
apple
CVE-2024-27863P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-27863 [MEDIUM] CVE-2024-27863: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27863
Component: Kernel
Impact: A local attacker may be able to determine kernel memory layout
Description: An information disclosure issue was addressed with improved private data redaction for log entries.
apple
CVE-2024-40833P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40833 [MEDIUM] CVE-2024-40833: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40833
Component: Shortcuts
Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-40823P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40823 [MEDIUM] CVE-2024-40823: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40823
Component: PackageKit
Impact: An app may be able to access user-sensitive data
Description: The issue was addressed with improved checks.
apple