cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 27 of 48
CVE-2024-40775P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40775 [MEDIUM] CVE-2024-40775: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40775 Component: AppleMobileFileIntegrity Impact: An app may be able to leak sensitive user information Description: A downgrade issue was addressed with additional code-signing restrictions.
apple
CVE-2023-40406P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-40406 [MEDIUM] CVE-2023-40406: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40406 Component: ColorSync Impact: An app may be able to read arbitrary files Description: The issue was addressed with improved checks.
apple
CVE-2024-40850P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-40850 [MEDIUM] CVE-2024-40850: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-40850 Component: Game Center Impact: An app may be able to access user-sensitive data Description: A file access issue was addressed with improved input validation.
apple
CVE-2024-44239P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44239 [MEDIUM] CVE-2024-44239: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44239 Component: Kernel Impact: An app may be able to leak sensitive kernel state Description: An information disclosure issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-42893P4MEDIUMCVSS 5.5v14.52024-05-13
CVE-2023-42893 [MEDIUM] CVE-2023-42893: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2023-42893 Component: Libsystem Impact: An app may be able to access protected user data Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
apple
CVE-2024-27884P4MEDIUMCVSS 5.5v14.52024-05-13
CVE-2024-27884 [MEDIUM] CVE-2024-27884: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27884 Component: Transparency Impact: An app may be able to access user-sensitive data Description: This issue was addressed with a new entitlement.
apple
CVE-2024-23236P4MEDIUMCVSS 5.5v14.52024-05-13
CVE-2024-23236 [MEDIUM] CVE-2024-23236: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-23236 Component: CFNetwork Impact: An app may be able to read arbitrary files Description: A correctness issue was addressed with improved checks.
apple
CVE-2026-20675P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20675 [MEDIUM] CVE-2026-20675: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20675 Component: ImageIO Impact: Processing a maliciously crafted image may lead to disclosure of user information Description: The issue was addressed with improved bounds checks.
apple
CVE-2024-44278P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44278 [MEDIUM] CVE-2024-44278: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44278 Component: Siri Impact: A sandboxed app may be able to access sensitive user data in system logs Description: An information disclosure issue was addressed with improved private data redaction for log entries.
apple
CVE-2024-23272P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-23272 [MEDIUM] CVE-2024-23272: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-23272 Component: Storage Services Impact: An attacker may gain access to protected parts of the file system Description: A logic issue was addressed with improved checks.
apple
CVE-2026-20634P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20634 [MEDIUM] CVE-2026-20634: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20634 Component: ImageIO Impact: Processing a maliciously crafted image may result in disclosure of process memory Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43314P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43314 [MEDIUM] CVE-2025-43314: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43314 Component: StorageKit Impact: An app may be able to access sensitive user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-43417P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-43417 [MEDIUM] CVE-2025-43417: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-43417 Component: File Bookmark Impact: An app may be able to access user-sensitive data Description: A path handling issue was addressed with improved logic.
apple
CVE-2024-40847P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-40847 [MEDIUM] CVE-2024-40847: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-40847 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: The issue was addressed with additional code-signing restrictions.
apple
CVE-2024-40855P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-40855 [MEDIUM] CVE-2024-40855: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-40855 Component: DiskArbitration Impact: A sandboxed app may be able to access sensitive user data Description: The issue was addressed with improved checks.
apple
CVE-2024-44177P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-44177 [MEDIUM] CVE-2024-44177: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-44177 Component: Dock Impact: An app may be able to access user-sensitive data Description: A privacy issue was addressed by removing sensitive data.
apple
CVE-2024-44184P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-44184 [MEDIUM] CVE-2024-44184: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-44184 Component: Transparency Impact: An app may be able to access user-sensitive data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42935P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42935 [MEDIUM] CVE-2023-42935: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42935 Component: LoginWindow Impact: A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-43446P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43446 [MEDIUM] CVE-2025-43446: macOS Sonoma 14.8.2 Apple Security Update: About the security content of macOS Sonoma 14.8.2 Product: macOS Sonoma Version: 14.8.2 CVE: CVE-2025-43446 Component: Assets Impact: An app may be able to modify protected parts of the file system Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-24271P4MEDIUMCVSS 5.4v14.7.52025-03-31
CVE-2025-24271 [MEDIUM] CVE-2025-24271: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24271 Component: AirPlay Impact: An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing Description: An access issue was addressed with improved access restrictions.
apple
Apple Macos Sonoma vulnerabilities | cvebase