Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 32 of 48
CVE-2024-27809P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-27809 [MEDIUM] CVE-2024-27809: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-27809
Component: Music
Impact: An app may be able to access user-sensitive data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-24144P4MEDIUMCVSS 5.5v14.7.62025-05-12
CVE-2025-24144 [MEDIUM] CVE-2025-24144: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-24144
Component: Kernel
Impact: An app may be able to leak sensitive kernel state
Description: An information disclosure issue was addressed by removing the vulnerable code.
apple
CVE-2025-43335P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43335 [MEDIUM] CVE-2025-43335: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43335
Component: Security
Impact: An app may be able to access user-sensitive data
Description: The issue was addressed by adding additional logic.
apple
CVE-2025-43322P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43322 [MEDIUM] CVE-2025-43322: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43322
Component: Admin Framework
Impact: An app may be able to access user-sensitive data
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43479P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43479 [MEDIUM] CVE-2025-43479: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43479
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43391P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43391 [MEDIUM] CVE-2025-43391: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43391
Component: Photos
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved handling of temporary files.
apple
CVE-2025-31220P4MEDIUMCVSS 5.5v14.7.62025-05-12
CVE-2025-31220 [MEDIUM] CVE-2025-31220: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31220
Component: Weather
Impact: A malicious app may be able to read sensitive location information
Description: A privacy issue was addressed by removing sensitive data.
apple
CVE-2025-43380P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43380 [MEDIUM] CVE-2025-43380: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43380
Component: Shortcuts
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2025-43513P4MEDIUMCVSS 5.5v14.8.32025-12-12
CVE-2025-43513 [MEDIUM] CVE-2025-43513: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-43513
Component: MDM Configuration Tools
Impact: An app may be able to read sensitive location information
Description: A permissions issue was addressed by removing the vulnerable code.
apple
CVE-2025-43396P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43396 [MEDIUM] CVE-2025-43396: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43396
Component: Installer
Impact: A sandboxed app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43498P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43498 [MEDIUM] CVE-2025-43498: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43498
Component: FileProvider
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-43403P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2025-43403 [MEDIUM] CVE-2025-43403: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-43403
Component: Compression
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-43499P4MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43499 [MEDIUM] CVE-2025-43499: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43499
Component: Shortcuts
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2026-20653P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20653 [MEDIUM] CVE-2026-20653: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20653
Component: Shortcuts
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-43345P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43345 [MEDIUM] CVE-2025-43345: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43345
Component: Kernel
Impact: An app may be able to access sensitive user data
Description: A correctness issue was addressed with improved checks.
apple
CVE-2025-43313P4MEDIUMCVSS 5.5v14.7.72025-07-29
CVE-2025-43313 [MEDIUM] CVE-2025-43313: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43313
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2026-20627P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20627 [MEDIUM] CVE-2026-20627: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20627
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
apple
CVE-2026-20612P4MEDIUMCVSS 5.5v14.8.42026-02-11
CVE-2026-20612 [MEDIUM] CVE-2026-20612: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20612
Component: Spotlight
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved checks.
apple
CVE-2024-27877P4MEDIUMCVSS 6.1v14.62024-07-29
CVE-2024-27877 [MEDIUM] CVE-2024-27877: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27877
Component: AppleVA
Impact: Processing a maliciously crafted file may lead to unexpected app termination
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-24130P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-24130 [MEDIUM] CVE-2025-24130: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24130
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: The issue was addressed with improved checks.
apple