Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 28 of 48
CVE-2025-43530P4MEDIUMCVSS 5.5v14.8.32025-12-12
CVE-2025-43530 [MEDIUM] CVE-2025-43530: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-43530
Component: VoiceOver
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved checks.
apple
CVE-2025-43315P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43315 [MEDIUM] CVE-2025-43315: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43315
Component: MigrationKit
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2026-20694P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20694 [MEDIUM] CVE-2026-20694: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20694
Component: MigrationKit
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with improved handling of symlinks.
apple
CVE-2025-43379P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43379 [MEDIUM] CVE-2025-43379: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43379
Component: AppleMobileFileIntegrity
Impact: An app may be able to access protected user data
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43334P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43334 [MEDIUM] CVE-2025-43334: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43334
Component: Spotlight
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-31242P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-31242 [MEDIUM] CVE-2025-31242: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-31242
Component: StoreKit
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-43411P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43411 [MEDIUM] CVE-2025-43411: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43411
Component: PackageKit
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2025-43509P4MEDIUMCVSS 5.5v14.8.32025-12-12
CVE-2025-43509 [MEDIUM] CVE-2025-43509: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-43509
Component: Networking
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved data protection.
apple
CVE-2024-44205P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-44205 [MEDIUM] CVE-2024-44205: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-44205
Component: Siri
Impact: A sandboxed app may be able to access sensitive user data in system logs
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-46283P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-46283 [MEDIUM] CVE-2025-46283: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46283
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved validation.
apple
CVE-2025-46276P4MEDIUMCVSS 5.5v14.8.32025-12-12
CVE-2025-46276 [MEDIUM] CVE-2025-46276: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-46276
Component: Messages
Impact: An app may be able to access sensitive user data
Description: An information disclosure issue was addressed with improved privacy controls.
apple
CVE-2025-43477P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43477 [MEDIUM] CVE-2025-43477: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43477
Component: Siri
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2026-20624P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20624 [MEDIUM] CVE-2026-20624: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20624
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: An injection issue was addressed with improved validation.
apple
CVE-2026-20670P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20670 [MEDIUM] CVE-2026-20670: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20670
Component: AppleEvents
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-31235P4MEDIUMCVSS 6.5v14.7.62025-05-12
CVE-2025-31235 [MEDIUM] CVE-2025-31235: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31235
Component: Audio
Impact: An app may be able to cause unexpected system termination
Description: A double free issue was addressed with improved memory management.
apple
CVE-2025-43238P4MEDIUMCVSS 6.2v14.7.72025-07-29
CVE-2025-43238 [MEDIUM] CVE-2025-43238: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43238
Component: Xsan
Impact: An app may be able to cause unexpected system termination
Description: An integer overflow was addressed with improved input validation.
apple
CVE-2024-27816P4MEDIUMCVSS 5.5v14.52024-05-13
CVE-2024-27816 [MEDIUM] CVE-2024-27816: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27816
Component: AppleMobileFileIntegrity
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-27810P4MEDIUMCVSS 5.5v14.52024-05-13
CVE-2024-27810 [MEDIUM] CVE-2024-27810: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27810
Component: Maps
Impact: An app may be able to read sensitive location information
Description: A path handling issue was addressed with improved validation.
apple
CVE-2024-40780P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40780 [MEDIUM] CVE-2024-40780: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40780
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2025-24103P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-24103 [MEDIUM] CVE-2025-24103: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24103
Component: Security
Impact: An app may be able to access protected user data
Description: This issue was addressed with improved validation of symlinks.
apple