Apple Macos Sonoma vulnerabilities
959 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
959
CISA KEV
11
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL73HIGH289MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 43 of 48
CVE-2023-41988MEDIUMCVSS 6.8v14.12023-10-25
CVE-2023-41988 [MEDIUM] CVE-2023-41988: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41988
Component: Siri
Impact: An attacker with physical access may be able to use Siri to access sensitive user data
Description: This issue was addressed by restricting options offered on a locked device.
apple
CVE-2023-40444MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-40444 [MEDIUM] CVE-2023-40444: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-40444
Component: AppSandbox
Impact: An app may be able to access user-sensitive data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42953MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42953 [MEDIUM] CVE-2023-42953: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42953
Component: Game Center
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-42823MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42823 [MEDIUM] CVE-2023-42823: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42823
Component: CVE-2023-42823
apple
CVE-2023-42859MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42859 [MEDIUM] CVE-2023-42859: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42859
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: The issue was addressed with improved checks.
apple
CVE-2023-28826MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-28826 [MEDIUM] CVE-2023-28826: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-28826
Component: MediaRemote
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2023-41982MEDIUMCVSS 4.6v14.12023-10-25
CVE-2023-41982 [MEDIUM] CVE-2023-41982: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41982
Component: Siri
Impact: An attacker with physical access may be able to use Siri to access sensitive user data
Description: This issue was addressed by restricting options offered on a locked device.
apple
CVE-2023-42946MEDIUMCVSS 5.5v14.12023-10-25
CVE-2023-42946 [MEDIUM] CVE-2023-42946: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42946
Component: CVE-2023-42946
apple
CVE-2023-40405LOWCVSS 3.3v14.12023-10-25
CVE-2023-40405 [LOW] CVE-2023-40405: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-40405
Component: Maps
Impact: An app may be able to read sensitive location information
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-42857LOWCVSS 3.3v14.12023-10-25
CVE-2023-42857 [LOW] CVE-2023-42857: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42857
Component: Contacts
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2023-36191UNKNOWNv14.12023-10-25
CVE-2023-36191 CVE-2023-36191: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-36191
Component: CVE-2023-36191
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-38408CRITICALCVSS 9.8v142023-09-26
CVE-2023-38408 [CRITICAL] CVE-2023-38408: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-38408
Component: OpenSSH
Impact: A vulnerability was discovered in OpenSSHs remote forwarding
Description: This issue was addressed by updating OpenSSH to 9.3p2
apple
CVE-2023-40455CRITICALCVSS 10.0v142023-09-26
CVE-2023-40455 [CRITICAL] CVE-2023-40455: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40455
Component: NetFSFramework
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-40436CRITICALCVSS 9.1v142023-09-26
CVE-2023-40436 [CRITICAL] CVE-2023-40436: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40436
Component: IOAcceleratorFamily
Impact: An attacker may be able to cause unexpected system termination or read kernel memory
Description: The issue was addressed with improved bounds checks.
apple
CVE-2023-40400CRITICALCVSS 9.8v142023-09-26
CVE-2023-40400 [CRITICAL] CVE-2023-40400: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40400
Component: LaunchServices
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
apple
CVE-2023-40414CRITICALCVSS 9.8v142023-09-26
CVE-2023-40414 [CRITICAL] CVE-2023-40414: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40414
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2023-38586CRITICALCVSS 10.0v142023-09-26
CVE-2023-38586 [CRITICAL] CVE-2023-38586: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-38586
Component: Image Capture
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2023-42870HIGHCVSS 7.8v142023-09-26
CVE-2023-42870 [HIGH] CVE-2023-42870: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42870
Component: Kernel
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2023-40454HIGHCVSS 7.1v142023-09-26
CVE-2023-40454 [HIGH] CVE-2023-40454: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40454
Component: LaunchServices
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved checks.
apple
CVE-2023-40393HIGHCVSS 7.5v142023-09-26
CVE-2023-40393 [HIGH] CVE-2023-40393: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40393
Component: Photos
Impact: Photos in the Hidden Photos Album may be viewed without authentication
Description: An authentication issue was addressed with improved state management.
apple