Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 4 of 48
CVE-2023-38709P3HIGHCVSS 7.3v14.62024-07-29
CVE-2023-38709 [HIGH] CVE-2023-38709: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2023-38709
Component: AirDrop
Impact: A file received from AirDrop may not have the quarantine flag applied
Description: This issue was addressed through improved state management.
apple
CVE-2025-24237P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24237 [CRITICAL] CVE-2025-24237: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24237
Component: BiometricKit
Impact: An app may be able to cause unexpected system termination
Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2024-40815P3HIGHCVSS 7.5v14.62024-07-29
CVE-2024-40815 [HIGH] CVE-2024-40815: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40815
Component: DiskArbitration
Impact: A person with physical access to an unlocked Mac may be able to gain root code execution
Description: The issue was addressed with improved checks.
apple
CVE-2025-24154P3CRITICALCVSS 9.1v14.7.32025-01-27
CVE-2025-24154 [CRITICAL] CVE-2025-24154: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24154
Component: WebContentFilter
Impact: An attacker may be able to cause unexpected system termination or corrupt kernel memory
Description: An out-of-bounds write was addressed with improved input validation.
apple
CVE-2023-42910P3HIGHCVSS 8.8v14.22023-12-11
CVE-2023-42910 [HIGH] CVE-2023-42910: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42910
Component: AppleGraphicsControl
Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2025-24254P3HIGHCVSS 8.8v14.7.52025-03-31
CVE-2025-24254 [HIGH] CVE-2025-24254: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24254
Component: Software Update
Impact: A user may be able to elevate privileges
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2026-20616P3HIGHCVSS 8.8v14.8.42026-02-11
CVE-2026-20616 [HIGH] CVE-2026-20616: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20616
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected app termination
Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-31194P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-31194 [CRITICAL] CVE-2025-31194: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31194
Component: Shortcuts
Impact: A Shortcut may run with admin privileges without authentication
Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-43359P3CRITICALCVSS 9.8v14.82025-09-15
CVE-2025-43359 [CRITICAL] CVE-2025-43359: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43359
Component: Kernel
Impact: A UDP server socket bound to a local interface may become bound to all interfaces
Description: A logic issue was addressed with improved state management.
apple
CVE-2025-26465P3MEDIUMCVSS 6.8v14.7.62025-05-12
CVE-2025-26465 [MEDIUM] CVE-2025-26465: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-26465
Component: CVE-2025-26465
apple
CVE-2025-30448P3CRITICALCVSS 9.1v14.7.62025-05-12
CVE-2025-30448 [CRITICAL] CVE-2025-30448: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-30448
Component: DiskArbitration
Impact: An app may be able to gain root privileges
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42913P3HIGHCVSS 8.8v14.22023-12-11
CVE-2023-42913 [HIGH] CVE-2023-42913: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42913
Component: System Settings
Impact: Remote Login sessions may be able to obtain full disk access permissions
Description: This issue was addressed through improved state management.
apple
CVE-2024-27815P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27815 [HIGH] CVE-2024-27815: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27815
Component: Kernel
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: An out-of-bounds write issue was addressed with improved input validation.
apple
CVE-2025-43187P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-43187 [HIGH] CVE-2025-43187: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43187
Component: Disk Images
Impact: Running an hdiutil command may unexpectedly execute arbitrary code
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-30433P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30433 [CRITICAL] CVE-2025-30433: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30433
Component: Shortcuts
Impact: A shortcut may be able to access files that are normally inaccessible to the Shortcuts app
Description: This issue was addressed with improved access restrictions.
apple
CVE-2026-20660P3HIGHCVSS 7.5v14.8.42026-02-11
CVE-2026-20660 [HIGH] CVE-2026-20660: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20660
Component: CFNetwork
Impact: A remote user may be able to write arbitrary files
Description: A path handling issue was addressed with improved logic.
apple
CVE-2025-24195P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24195 [CRITICAL] CVE-2025-24195: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24195
Component: Libinfo
Impact: A user may be able to elevate privileges
Description: An integer overflow was addressed with improved input validation.
apple
CVE-2025-43253P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43253 [CRITICAL] CVE-2025-43253: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43253
Component: AppleMobileFileIntegrity
Impact: A malicious app may be able to launch arbitrary binaries on a trusted device
Description: This issue was addressed with improved input validation.
apple
CVE-2025-31246P3HIGHCVSS 8.8v14.7.62025-05-12
CVE-2025-31246 [HIGH] CVE-2025-31246: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31246
Component: About Apple security updates
Impact: Connecting to a malicious AFP server may corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43358P3HIGHCVSS 8.8v14.82025-09-15
CVE-2025-43358 [HIGH] CVE-2025-43358: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43358
Component: Shortcuts
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
apple