Apple Macos Sonoma vulnerabilities

959 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
959
CISA KEV
11
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL73HIGH289MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 43 of 48
CVE-2023-41988MEDIUMCVSS 6.8v14.12023-10-25
CVE-2023-41988 [MEDIUM] CVE-2023-41988: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-41988 Component: Siri Impact: An attacker with physical access may be able to use Siri to access sensitive user data Description: This issue was addressed by restricting options offered on a locked device.
apple
CVE-2023-40444MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-40444 [MEDIUM] CVE-2023-40444: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-40444 Component: AppSandbox Impact: An app may be able to access user-sensitive data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42953MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42953 [MEDIUM] CVE-2023-42953: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42953 Component: Game Center Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42823MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42823 [MEDIUM] CVE-2023-42823: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42823 Component: CVE-2023-42823
apple
CVE-2023-42859MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42859 [MEDIUM] CVE-2023-42859: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42859 Component: PackageKit Impact: An app may be able to modify protected parts of the file system Description: The issue was addressed with improved checks.
apple
CVE-2023-28826MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-28826 [MEDIUM] CVE-2023-28826: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-28826 Component: MediaRemote Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2023-41982MEDIUMCVSS 4.6v14.12023-10-25
CVE-2023-41982 [MEDIUM] CVE-2023-41982: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-41982 Component: Siri Impact: An attacker with physical access may be able to use Siri to access sensitive user data Description: This issue was addressed by restricting options offered on a locked device.
apple
CVE-2023-42946MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42946 [MEDIUM] CVE-2023-42946: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42946 Component: CVE-2023-42946
apple
CVE-2023-40405LOWCVSS 3.3v14.12023-10-25
CVE-2023-40405 [LOW] CVE-2023-40405: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-40405 Component: Maps Impact: An app may be able to read sensitive location information Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-42857LOWCVSS 3.3v14.12023-10-25
CVE-2023-42857 [LOW] CVE-2023-42857: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42857 Component: Contacts Impact: An app may be able to access sensitive user data Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-36191UNKNOWNv14.12023-10-25
CVE-2023-36191 CVE-2023-36191: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-36191 Component: CVE-2023-36191 Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-38408CRITICALCVSS 9.8v142023-09-26
CVE-2023-38408 [CRITICAL] CVE-2023-38408: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-38408 Component: OpenSSH Impact: A vulnerability was discovered in OpenSSHs remote forwarding Description: This issue was addressed by updating OpenSSH to 9.3p2
apple
CVE-2023-40455CRITICALCVSS 10.0v142023-09-26
CVE-2023-40455 [CRITICAL] CVE-2023-40455: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40455 Component: NetFSFramework Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-40436CRITICALCVSS 9.1v142023-09-26
CVE-2023-40436 [CRITICAL] CVE-2023-40436: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40436 Component: IOAcceleratorFamily Impact: An attacker may be able to cause unexpected system termination or read kernel memory Description: The issue was addressed with improved bounds checks.
apple
CVE-2023-40400CRITICALCVSS 9.8v142023-09-26
CVE-2023-40400 [CRITICAL] CVE-2023-40400: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40400 Component: LaunchServices Impact: An app may bypass Gatekeeper checks Description: A logic issue was addressed with improved checks.
apple
CVE-2023-40414CRITICALCVSS 9.8v142023-09-26
CVE-2023-40414 [CRITICAL] CVE-2023-40414: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40414 Component: WebKit Impact: Processing web content may lead to arbitrary code execution Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2023-38586CRITICALCVSS 10.0v142023-09-26
CVE-2023-38586 [CRITICAL] CVE-2023-38586: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-38586 Component: Image Capture Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2023-42870HIGHCVSS 7.8v142023-09-26
CVE-2023-42870 [HIGH] CVE-2023-42870: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-42870 Component: Kernel Impact: An app may be able to execute arbitrary code with kernel privileges Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2023-40454HIGHCVSS 7.1v142023-09-26
CVE-2023-40454 [HIGH] CVE-2023-40454: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40454 Component: LaunchServices Impact: An app may bypass Gatekeeper checks Description: A logic issue was addressed with improved checks.
apple
CVE-2023-40393HIGHCVSS 7.5v142023-09-26
CVE-2023-40393 [HIGH] CVE-2023-40393: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40393 Component: Photos Impact: Photos in the Hidden Photos Album may be viewed without authentication Description: An authentication issue was addressed with improved state management.
apple