cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 29 of 48
CVE-2024-27789P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-27789 [MEDIUM] CVE-2024-27789: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-27789 Component: Foundation Impact: An app may be able to access user-sensitive data Description: A logic issue was addressed with improved checks.
apple
CVE-2024-40836P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40836 [MEDIUM] CVE-2024-40836: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40836 Component: Shortcuts Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user Description: A logic issue was addressed with improved checks.
apple
CVE-2023-40429P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-40429 [MEDIUM] CVE-2023-40429: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40429 Component: Kernel Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with improved validation.
apple
CVE-2024-44196P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44196 [MEDIUM] CVE-2024-44196: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44196 Component: PackageKit Impact: An app may be able to modify protected parts of the file system Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2024-44279P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44279 [MEDIUM] CVE-2024-44279: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44279 Component: Shortcuts Impact: A malicious app may use shortcuts to access restricted files Description: A logic issue was addressed with improved checks.
apple
CVE-2024-44151P4MEDIUMCVSS 5.5v14.72024-09-16
CVE-2024-44151 [MEDIUM] CVE-2024-44151: macOS Sonoma 14.7 Apple Security Update: About the security content of macOS Sonoma 14.7 Product: macOS Sonoma Version: 14.7 CVE: CVE-2024-44151 Component: Automator Impact: An Automator Quick Action workflow may be able to bypass Gatekeeper Description: This issue was addressed by adding an additional prompt for user consent.
apple
CVE-2025-24109P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-24109 [MEDIUM] CVE-2025-24109: macOS Sonoma 14.7.3 Apple Security Update: About the security content of macOS Sonoma 14.7.3 Product: macOS Sonoma Version: 14.7.3 CVE: CVE-2025-24109 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: A downgrade issue was addressed with additional code-signing restrictions.
apple
CVE-2025-31191P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-31191 [MEDIUM] CVE-2025-31191: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-31191 Component: CoreServices Impact: An app may be able to access sensitive user data Description: This issue was addressed through improved state management.
apple
CVE-2023-51384P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2023-51384 [MEDIUM] CVE-2023-51384: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2023-51384 Component: CVE-2023-51384
apple
CVE-2023-42823P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42823 [MEDIUM] CVE-2023-42823: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42823 Component: CVE-2023-42823
apple
CVE-2023-42884P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42884 [MEDIUM] CVE-2023-42884: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42884 Component: AVEVideoEncoder Impact: An app may be able to disclose kernel memory Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2024-40779P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40779 [MEDIUM] CVE-2024-40779: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40779 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2023-41070P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-41070 [MEDIUM] CVE-2023-41070: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-41070 Component: Share Sheet Impact: An app may be able to access sensitive data logged when a user shares a link Description: A logic issue was addressed with improved checks.
apple
CVE-2024-44215P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44215 [MEDIUM] CVE-2024-44215: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44215 Component: ImageIO Impact: Processing an image may result in disclosure of process memory Description: This issue was addressed with improved checks.
apple
CVE-2025-43285P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43285 [MEDIUM] CVE-2025-43285: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43285 Component: AppSandbox Impact: An app may be able to access protected user data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42891P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42891 [MEDIUM] CVE-2023-42891: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42891 Component: IOKit Impact: An app may be able to monitor keystrokes without user permission Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-30447P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30447 [MEDIUM] CVE-2025-30447: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-30447 Component: Foundation Impact: An app may be able to access sensitive user data Description: The issue was resolved by sanitizing logging
apple
CVE-2024-44269P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44269 [MEDIUM] CVE-2024-44269: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44269 Component: Shortcuts Impact: A malicious app may use shortcuts to access restricted files Description: A logic issue was addressed with improved checks.
apple
CVE-2025-30438P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30438 [MEDIUM] CVE-2025-30438: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-30438 Component: Share Sheet Impact: A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started Description: This issue was addressed with improved access restrictions.
apple
CVE-2025-31251P4MEDIUMCVSS 5.5v14.7.62025-05-12
CVE-2025-31251 [MEDIUM] CVE-2025-31251: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-31251 Component: AppleJPEG Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory Description: The issue was addressed with improved input sanitization.
apple
Apple Macos Sonoma vulnerabilities | cvebase