cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 36 of 48
CVE-2025-43305P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43305 [MEDIUM] CVE-2025-43305: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43305 Component: CoreServices Impact: A malicious app may be able to access private information Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43321P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43321 [MEDIUM] CVE-2025-43321: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43321 Component: AppKit Impact: An app may be able to access protected user data Description: The issue was resolved by blocking unsigned services from launching on Intel Macs.
apple
CVE-2025-31269P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-31269 [MEDIUM] CVE-2025-31269: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-31269 Component: Printing Impact: An app may be able to access protected user data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42896P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42896 [MEDIUM] CVE-2023-42896: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42896 Component: Assets Impact: An app may be able to modify protected parts of the file system Description: An issue was addressed with improved handling of temporary files.
apple
CVE-2023-40390P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-40390 [MEDIUM] CVE-2023-40390: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-40390 Component: Share Sheet Impact: An app may be able to access user-sensitive data Description: A privacy issue was addressed by moving sensitive data to a protected location.
apple
CVE-2023-40411P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-40411 [MEDIUM] CVE-2023-40411: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40411 Component: FileProvider Impact: An app may be able to access user-sensitive data Description: This issue was addressed with improved data protection.
apple
CVE-2023-42878P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42878 [MEDIUM] CVE-2023-42878: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42878 Component: Share Sheet Impact: An app may be able to access sensitive user data Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-42858P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42858 [MEDIUM] CVE-2023-42858: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42858 Component: WindowServer Impact: An app may be able to access user-sensitive data Description: The issue was addressed with improved checks.
apple
CVE-2025-24142P4MEDIUMCVSS 5.5v14.7.62025-05-12
CVE-2025-24142 [MEDIUM] CVE-2025-24142: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-24142 Component: Notification Center Impact: An app may be able to access sensitive user data Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2024-27888P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-27888 [MEDIUM] CVE-2024-27888: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-27888 Component: PackageKit Impact: An app may be able to modify protected parts of the file system Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
apple
CVE-2023-42943P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-42943 [MEDIUM] CVE-2023-42943: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-42943 Component: Clock Impact: An app may be able to read sensitive location information Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-30440P4MEDIUMCVSS 5.5v14.7.62025-05-12
CVE-2025-30440 [MEDIUM] CVE-2025-30440: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-30440 Component: Libinfo Impact: An app may be able to bypass ASLR Description: The issue was addressed with improved checks.
apple
CVE-2024-27792P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-27792 [MEDIUM] CVE-2024-27792: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-27792 Component: TCC Impact: An app may be able to access user-sensitive data Description: This issue was addressed by adding an additional prompt for user consent.
apple
CVE-2023-42953P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42953 [MEDIUM] CVE-2023-42953: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42953 Component: Game Center Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24148P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24148 [MEDIUM] CVE-2025-24148: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24148 Component: LaunchServices Impact: A malicious JAR file may bypass Gatekeeper checks Description: This issue was addressed with improved handling of executable types.
apple
CVE-2025-31261P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-31261 [MEDIUM] CVE-2025-31261: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-31261 Component: StorageKit Impact: An app may be able to access protected user data Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2025-24183P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-24183 [MEDIUM] CVE-2025-24183: macOS Sonoma 14.7.3 Apple Security Update: About the security content of macOS Sonoma 14.7.3 Product: macOS Sonoma Version: 14.7.3 CVE: CVE-2025-24183 Component: Perl Impact: A local user may be able to modify protected parts of the file system Description: The issue was addressed with improved checks.
apple
CVE-2025-43445P4MEDIUMCVSS 4.3v14.8.22025-11-03
CVE-2025-43445 [MEDIUM] CVE-2025-43445: macOS Sonoma 14.8.2 Apple Security Update: About the security content of macOS Sonoma 14.8.2 Product: macOS Sonoma Version: 14.8.2 CVE: CVE-2025-43445 Component: CoreText Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2023-42918P4MEDIUMCVSS 6.3v142023-09-26
CVE-2023-42918 [MEDIUM] CVE-2023-42918: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-42918 Component: Model I/O Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43191P4MEDIUMCVSS 6.2v14.7.72025-07-29
CVE-2025-43191 [MEDIUM] CVE-2025-43191: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43191 Component: Admin Framework Impact: An app may be able to cause a denial-of-service Description: A path handling issue was addressed with improved validation.
apple