cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 45 of 48
CVE-2025-43259P4MEDIUMCVSS 4.6v14.7.72025-07-29
CVE-2025-43259 [MEDIUM] CVE-2025-43259: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43259 Component: WindowServer Impact: An attacker with physical access to a locked device may be able to view sensitive user information Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2023-41977P4MEDIUMCVSS 4.3v14.12023-10-25
CVE-2023-41977 [MEDIUM] CVE-2023-41977: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-41977 Component: Safari Impact: Visiting a malicious website may reveal browsing history Description: The issue was addressed with improved handling of caches.
apple
CVE-2023-42438P4MEDIUMCVSS 4.3v14.12023-10-25
CVE-2023-42438 [MEDIUM] CVE-2023-42438: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42438 Component: Safari Impact: Visiting a malicious website may lead to user interface spoofing Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2023-40388P4MEDIUMCVSS 4.3v142023-09-26
CVE-2023-40388 [MEDIUM] CVE-2023-40388: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40388 Component: Safari Impact: Safari may save photos to an unprotected location Description: A privacy issue was addressed with improved handling of temporary files.
apple
CVE-2023-40425P4MEDIUMCVSS 4.4v142023-09-26
CVE-2023-40425 [MEDIUM] CVE-2023-40425: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40425 Component: Sandbox Impact: An app with root privileges may be able to access private information Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-43310P4MEDIUMCVSS 4.4v14.82025-09-15
CVE-2025-43310 [MEDIUM] CVE-2025-43310: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-43310 Component: WindowServer Impact: An app may be able to trick a user into copying sensitive data to the pasteboard Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2025-43374P4MEDIUMCVSS 4.3v14.7.32025-01-27
CVE-2025-43374 [MEDIUM] CVE-2025-43374: macOS Sonoma 14.7.3 Apple Security Update: About the security content of macOS Sonoma 14.7.3 Product: macOS Sonoma Version: 14.7.3 CVE: CVE-2025-43374 Component: Wi-Fi Impact: An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2023-40422P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-40422 [MEDIUM] CVE-2023-40422: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40422 Component: QuartzCore Impact: An app may be able to cause a denial-of-service Description: The issue was addressed with improved memory handling.
apple
CVE-2024-27882P4MEDIUMCVSS 4.4v14.62024-07-29
CVE-2024-27882 [MEDIUM] CVE-2024-27882: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-27882 Component: PackageKit Impact: An app may be able to modify protected parts of the file system Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24136P4MEDIUMCVSS 4.4v14.7.32025-01-27
CVE-2025-24136 [MEDIUM] CVE-2025-24136: macOS Sonoma 14.7.3 Apple Security Update: About the security content of macOS Sonoma 14.7.3 Product: macOS Sonoma Version: 14.7.3 CVE: CVE-2025-24136 Component: Login Window Impact: A malicious app may be able to create symlinks to protected regions of the disk Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2024-27883P4MEDIUMCVSS 4.4v14.62024-07-29
CVE-2024-27883 [MEDIUM] CVE-2024-27883: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-27883 Component: PackageKit Impact: An app may be able to modify protected parts of the file system Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2024-40834P4MEDIUMCVSS 4.4v14.62024-07-29
CVE-2024-40834 [MEDIUM] CVE-2024-40834: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-40834 Component: Shortcuts Impact: A shortcut may be able to bypass sensitive Shortcuts app settings Description: This issue was addressed by adding an additional prompt for user consent.
apple
CVE-2025-24116P4MEDIUMCVSS 4.4v14.7.32025-01-27
CVE-2025-24116 [MEDIUM] CVE-2025-24116: macOS Sonoma 14.7.3 Apple Security Update: About the security content of macOS Sonoma 14.7.3 Product: macOS Sonoma Version: 14.7.3 CVE: CVE-2025-24116 Component: LaunchServices Impact: An app may be able to bypass Privacy preferences Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2026-20609P4MEDIUMCVSS 4.4v14.8.42026-02-11
CVE-2026-20609 [MEDIUM] CVE-2026-20609: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20609 Component: CoreMedia Impact: Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents Description: The issue was addressed with improved memory handling.
apple
CVE-2024-2004P4LOWCVSS 3.5v14.62024-07-29
CVE-2024-2004 [LOW] CVE-2024-2004: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-2004 Component: CVE-2024-2004
apple
CVE-2025-43226P4MEDIUMCVSS 4.0v14.7.72025-07-29
CVE-2025-43226 [MEDIUM] CVE-2025-43226: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43226 Component: CVE-2025-43226
apple
CVE-2025-43205P4MEDIUMCVSS 4.0v14.7.52025-03-31
CVE-2025-43205 [MEDIUM] CVE-2025-43205: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-43205 Component: Audio Impact: An app may be able to bypass ASLR Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2023-42934P4MEDIUMCVSS 4.2v142023-09-26
CVE-2023-42934 [MEDIUM] CVE-2023-42934: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-42934 Component: Photos Storage Impact: An app with root privileges may be able to access private information Description: An information disclosure issue was addressed by removing the vulnerable code.
apple
CVE-2025-43250P4MEDIUMCVSS 4.0v14.7.72025-07-29
CVE-2025-43250 [MEDIUM] CVE-2025-43250: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43250 Component: SharedFileList Impact: An app may be able to break out of its sandbox Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-43206P4MEDIUMCVSS 4.0v14.7.72025-07-29
CVE-2025-43206 [MEDIUM] CVE-2025-43206: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43206 Component: System Settings Impact: An app may be able to access protected user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple