Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 36 of 48
CVE-2025-43305P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43305 [MEDIUM] CVE-2025-43305: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43305
Component: CoreServices
Impact: A malicious app may be able to access private information
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43321P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-43321 [MEDIUM] CVE-2025-43321: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43321
Component: AppKit
Impact: An app may be able to access protected user data
Description: The issue was resolved by blocking unsigned services from launching on Intel Macs.
apple
CVE-2025-31269P4MEDIUMCVSS 5.5v14.82025-09-15
CVE-2025-31269 [MEDIUM] CVE-2025-31269: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-31269
Component: Printing
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42896P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-42896 [MEDIUM] CVE-2023-42896: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42896
Component: Assets
Impact: An app may be able to modify protected parts of the file system
Description: An issue was addressed with improved handling of temporary files.
apple
CVE-2023-40390P4MEDIUMCVSS 5.5v14.22023-12-11
CVE-2023-40390 [MEDIUM] CVE-2023-40390: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-40390
Component: Share Sheet
Impact: An app may be able to access user-sensitive data
Description: A privacy issue was addressed by moving sensitive data to a protected location.
apple
CVE-2023-40411P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-40411 [MEDIUM] CVE-2023-40411: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40411
Component: FileProvider
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with improved data protection.
apple
CVE-2023-42878P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42878 [MEDIUM] CVE-2023-42878: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42878
Component: Share Sheet
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-42858P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42858 [MEDIUM] CVE-2023-42858: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42858
Component: WindowServer
Impact: An app may be able to access user-sensitive data
Description: The issue was addressed with improved checks.
apple
CVE-2025-24142P4MEDIUMCVSS 5.5v14.7.62025-05-12
CVE-2025-24142 [MEDIUM] CVE-2025-24142: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-24142
Component: Notification Center
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2024-27888P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-27888 [MEDIUM] CVE-2024-27888: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-27888
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
apple
CVE-2023-42943P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-42943 [MEDIUM] CVE-2023-42943: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42943
Component: Clock
Impact: An app may be able to read sensitive location information
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-30440P4MEDIUMCVSS 5.5v14.7.62025-05-12
CVE-2025-30440 [MEDIUM] CVE-2025-30440: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-30440
Component: Libinfo
Impact: An app may be able to bypass ASLR
Description: The issue was addressed with improved checks.
apple
CVE-2024-27792P4MEDIUMCVSS 5.5v14.42024-03-07
CVE-2024-27792 [MEDIUM] CVE-2024-27792: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-27792
Component: TCC
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed by adding an additional prompt for user consent.
apple
CVE-2023-42953P4MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42953 [MEDIUM] CVE-2023-42953: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42953
Component: Game Center
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24148P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-24148 [MEDIUM] CVE-2025-24148: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24148
Component: LaunchServices
Impact: A malicious JAR file may bypass Gatekeeper checks
Description: This issue was addressed with improved handling of executable types.
apple
CVE-2025-31261P4MEDIUMCVSS 5.5v14.7.52025-03-31
CVE-2025-31261 [MEDIUM] CVE-2025-31261: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31261
Component: StorageKit
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2025-24183P4MEDIUMCVSS 5.5v14.7.32025-01-27
CVE-2025-24183 [MEDIUM] CVE-2025-24183: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24183
Component: Perl
Impact: A local user may be able to modify protected parts of the file system
Description: The issue was addressed with improved checks.
apple
CVE-2025-43445P4MEDIUMCVSS 4.3v14.8.22025-11-03
CVE-2025-43445 [MEDIUM] CVE-2025-43445: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43445
Component: CoreText
Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2023-42918P4MEDIUMCVSS 6.3v142023-09-26
CVE-2023-42918 [MEDIUM] CVE-2023-42918: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42918
Component: Model I/O
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43191P4MEDIUMCVSS 6.2v14.7.72025-07-29
CVE-2025-43191 [MEDIUM] CVE-2025-43191: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43191
Component: Admin Framework
Impact: An app may be able to cause a denial-of-service
Description: A path handling issue was addressed with improved validation.
apple