Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 34 of 48
CVE-2024-40784P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40784 [MEDIUM] CVE-2024-40784: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40784
Component: ImageIO
Impact: Processing a maliciously crafted file may lead to unexpected app termination
Description: An integer overflow was addressed with improved input validation.
apple
CVE-2023-40541P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-40541 [MEDIUM] CVE-2023-40541: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40541
Component: Shortcuts
Impact: A shortcut may output sensitive user data without consent
Description: This issue was addressed by adding an additional prompt for user consent.
apple
CVE-2024-23224P4MEDIUMCVSS 5.5v14.32024-01-22
CVE-2024-23224 [MEDIUM] CVE-2024-23224: macOS Sonoma 14.3
Apple Security Update: About the security content of macOS Sonoma 14.3
Product: macOS Sonoma
Version: 14.3
CVE: CVE-2024-23224
Component: Finder
Impact: An app may be able to access sensitive user data
Description: The issue was addressed with improved checks.
apple
CVE-2023-32361P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-32361 [MEDIUM] CVE-2023-32361: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-32361
Component: AuthKit
Impact: An app may be able to access user-sensitive data
Description: The issue was addressed with improved handling of caches.
apple
CVE-2023-41067P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-41067 [MEDIUM] CVE-2023-41067: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-41067
Component: LaunchServices
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-30454P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30454 [MEDIUM] CVE-2025-30454: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30454
Component: CoreMedia Playback
Impact: A malicious app may be able to access private information
Description: A path handling issue was addressed with improved validation.
apple
CVE-2024-40824P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-40824 [MEDIUM] CVE-2024-40824: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40824
Component: Sandbox
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed through improved state management.
apple
CVE-2024-44273P4MEDIUMCVSS 5.5v14.7.12024-10-28
CVE-2024-44273 [MEDIUM] CVE-2024-44273: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44273
Component: CoreMedia Playback
Impact: A malicious app may be able to access private information
Description: This issue was addressed with improved handling of symlinks.
apple
CVE-2023-42900P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42900 [MEDIUM] CVE-2023-42900: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42900
Component: CoreMedia Playback
Impact: An app may be able to access user-sensitive data
Description: The issue was addressed with improved checks.
apple
CVE-2024-23229P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-23229 [MEDIUM] CVE-2024-23229: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23229
Component: Find My
Impact: A malicious application may be able to access Find My data
Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2025-24164P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24164 [MEDIUM] CVE-2025-24164: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24164
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: A logic issue was addressed with improved checks.
apple
CVE-2023-41072P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-41072 [MEDIUM] CVE-2023-41072: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41072
Component: Contacts
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-24236P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24236 [MEDIUM] CVE-2025-24236: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24236
Component: CoreMedia
Impact: An app may be able to access sensitive user data
Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2023-42924P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42924 [MEDIUM] CVE-2023-42924: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42924
Component: Archive Utility
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-27872P4MEDIUMCVSS 5.5v14.62024-07-29
CVE-2024-27872 [MEDIUM] CVE-2024-27872: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27872
Component: Security Initialization
Impact: An app may be able to access protected user data
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2023-28826P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-28826 [MEDIUM] CVE-2023-28826: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-28826
Component: MediaRemote
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2025-30450P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-30450 [MEDIUM] CVE-2025-30450: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30450
Component: Mail
Impact: "Block All Remote Content" may not apply for all mail previews
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2024-23279P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-23279 [MEDIUM] CVE-2024-23279: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23279
Component: MediaRemote
Impact: An app may be able to access user-sensitive data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-24215P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24215 [MEDIUM] CVE-2025-24215: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24215
Component: CloudKit
Impact: A malicious app may be able to access private information
Description: The issue was addressed with improved checks.
apple
CVE-2025-24092P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-24092 [MEDIUM] CVE-2025-24092: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24092
Component: TV App
Impact: An app may be able to read sensitive location information
Description: This issue was addressed with improved data protection.
apple