cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 4 of 48
CVE-2023-38709P3HIGHCVSS 7.3v14.62024-07-29
CVE-2023-38709 [HIGH] CVE-2023-38709: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2023-38709 Component: AirDrop Impact: A file received from AirDrop may not have the quarantine flag applied Description: This issue was addressed through improved state management.
apple
CVE-2025-24237P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24237 [CRITICAL] CVE-2025-24237: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24237 Component: BiometricKit Impact: An app may be able to cause unexpected system termination Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2024-40815P3HIGHCVSS 7.5v14.62024-07-29
CVE-2024-40815 [HIGH] CVE-2024-40815: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40815 Component: DiskArbitration Impact: A person with physical access to an unlocked Mac may be able to gain root code execution Description: The issue was addressed with improved checks.
apple
CVE-2025-24154P3CRITICALCVSS 9.1v14.7.32025-01-27
CVE-2025-24154 [CRITICAL] CVE-2025-24154: macOS Sonoma 14.7.3 Apple Security Update: About the security content of macOS Sonoma 14.7.3 Product: macOS Sonoma Version: 14.7.3 CVE: CVE-2025-24154 Component: WebContentFilter Impact: An attacker may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds write was addressed with improved input validation.
apple
CVE-2023-42910P3HIGHCVSS 8.8v14.22023-12-11
CVE-2023-42910 [HIGH] CVE-2023-42910: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42910 Component: AppleGraphicsControl Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution Description: Multiple memory corruption issues were addressed with improved input validation.
apple
CVE-2025-24254P3HIGHCVSS 8.8v14.7.52025-03-31
CVE-2025-24254 [HIGH] CVE-2025-24254: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24254 Component: Software Update Impact: A user may be able to elevate privileges Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2026-20616P3HIGHCVSS 8.8v14.8.42026-02-11
CVE-2026-20616 [HIGH] CVE-2026-20616: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20616 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-31194P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-31194 [CRITICAL] CVE-2025-31194: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-31194 Component: Shortcuts Impact: A Shortcut may run with admin privileges without authentication Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-43359P3CRITICALCVSS 9.8v14.82025-09-15
CVE-2025-43359 [CRITICAL] CVE-2025-43359: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43359 Component: Kernel Impact: A UDP server socket bound to a local interface may become bound to all interfaces Description: A logic issue was addressed with improved state management.
apple
CVE-2025-26465P3MEDIUMCVSS 6.8v14.7.62025-05-12
CVE-2025-26465 [MEDIUM] CVE-2025-26465: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-26465 Component: CVE-2025-26465
apple
CVE-2025-30448P3CRITICALCVSS 9.1v14.7.62025-05-12
CVE-2025-30448 [CRITICAL] CVE-2025-30448: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-30448 Component: DiskArbitration Impact: An app may be able to gain root privileges Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42913P3HIGHCVSS 8.8v14.22023-12-11
CVE-2023-42913 [HIGH] CVE-2023-42913: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42913 Component: System Settings Impact: Remote Login sessions may be able to obtain full disk access permissions Description: This issue was addressed through improved state management.
apple
CVE-2024-27815P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27815 [HIGH] CVE-2024-27815: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27815 Component: Kernel Impact: An app may be able to execute arbitrary code with kernel privileges Description: An out-of-bounds write issue was addressed with improved input validation.
apple
CVE-2025-43187P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-43187 [HIGH] CVE-2025-43187: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43187 Component: Disk Images Impact: Running an hdiutil command may unexpectedly execute arbitrary code Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-30433P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30433 [CRITICAL] CVE-2025-30433: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-30433 Component: Shortcuts Impact: A shortcut may be able to access files that are normally inaccessible to the Shortcuts app Description: This issue was addressed with improved access restrictions.
apple
CVE-2026-20660P3HIGHCVSS 7.5v14.8.42026-02-11
CVE-2026-20660 [HIGH] CVE-2026-20660: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20660 Component: CFNetwork Impact: A remote user may be able to write arbitrary files Description: A path handling issue was addressed with improved logic.
apple
CVE-2025-24195P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24195 [CRITICAL] CVE-2025-24195: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24195 Component: Libinfo Impact: A user may be able to elevate privileges Description: An integer overflow was addressed with improved input validation.
apple
CVE-2025-43253P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43253 [CRITICAL] CVE-2025-43253: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43253 Component: AppleMobileFileIntegrity Impact: A malicious app may be able to launch arbitrary binaries on a trusted device Description: This issue was addressed with improved input validation.
apple
CVE-2025-31246P3HIGHCVSS 8.8v14.7.62025-05-12
CVE-2025-31246 [HIGH] CVE-2025-31246: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-31246 Component: About Apple security updates Impact: Connecting to a malicious AFP server may corrupt kernel memory Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43358P3HIGHCVSS 8.8v14.82025-09-15
CVE-2025-43358 [HIGH] CVE-2025-43358: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43358 Component: Shortcuts Impact: A shortcut may be able to bypass sandbox restrictions Description: A permissions issue was addressed with additional sandbox restrictions.
apple
Apple Macos Sonoma vulnerabilities | cvebase