Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 45 of 48
CVE-2025-43259P4MEDIUMCVSS 4.6v14.7.72025-07-29
CVE-2025-43259 [MEDIUM] CVE-2025-43259: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43259
Component: WindowServer
Impact: An attacker with physical access to a locked device may be able to view sensitive user information
Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2023-41977P4MEDIUMCVSS 4.3v14.12023-10-25
CVE-2023-41977 [MEDIUM] CVE-2023-41977: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-41977
Component: Safari
Impact: Visiting a malicious website may reveal browsing history
Description: The issue was addressed with improved handling of caches.
apple
CVE-2023-42438P4MEDIUMCVSS 4.3v14.12023-10-25
CVE-2023-42438 [MEDIUM] CVE-2023-42438: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42438
Component: Safari
Impact: Visiting a malicious website may lead to user interface spoofing
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2023-40388P4MEDIUMCVSS 4.3v142023-09-26
CVE-2023-40388 [MEDIUM] CVE-2023-40388: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40388
Component: Safari
Impact: Safari may save photos to an unprotected location
Description: A privacy issue was addressed with improved handling of temporary files.
apple
CVE-2023-40425P4MEDIUMCVSS 4.4v142023-09-26
CVE-2023-40425 [MEDIUM] CVE-2023-40425: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40425
Component: Sandbox
Impact: An app with root privileges may be able to access private information
Description: A privacy issue was addressed with improved private data redaction for log entries.
apple
CVE-2025-43310P4MEDIUMCVSS 4.4v14.82025-09-15
CVE-2025-43310 [MEDIUM] CVE-2025-43310: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43310
Component: WindowServer
Impact: An app may be able to trick a user into copying sensitive data to the pasteboard
Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2025-43374P4MEDIUMCVSS 4.3v14.7.32025-01-27
CVE-2025-43374 [MEDIUM] CVE-2025-43374: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-43374
Component: Wi-Fi
Impact: An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2023-40422P4MEDIUMCVSS 5.5v142023-09-26
CVE-2023-40422 [MEDIUM] CVE-2023-40422: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40422
Component: QuartzCore
Impact: An app may be able to cause a denial-of-service
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-27882P4MEDIUMCVSS 4.4v14.62024-07-29
CVE-2024-27882 [MEDIUM] CVE-2024-27882: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27882
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-24136P4MEDIUMCVSS 4.4v14.7.32025-01-27
CVE-2025-24136 [MEDIUM] CVE-2025-24136: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24136
Component: Login Window
Impact: A malicious app may be able to create symlinks to protected regions of the disk
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2024-27883P4MEDIUMCVSS 4.4v14.62024-07-29
CVE-2024-27883 [MEDIUM] CVE-2024-27883: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-27883
Component: PackageKit
Impact: An app may be able to modify protected parts of the file system
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2024-40834P4MEDIUMCVSS 4.4v14.62024-07-29
CVE-2024-40834 [MEDIUM] CVE-2024-40834: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-40834
Component: Shortcuts
Impact: A shortcut may be able to bypass sensitive Shortcuts app settings
Description: This issue was addressed by adding an additional prompt for user consent.
apple
CVE-2025-24116P4MEDIUMCVSS 4.4v14.7.32025-01-27
CVE-2025-24116 [MEDIUM] CVE-2025-24116: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24116
Component: LaunchServices
Impact: An app may be able to bypass Privacy preferences
Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2026-20609P4MEDIUMCVSS 4.4v14.8.42026-02-11
CVE-2026-20609 [MEDIUM] CVE-2026-20609: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20609
Component: CoreMedia
Impact: Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-2004P4LOWCVSS 3.5v14.62024-07-29
CVE-2024-2004 [LOW] CVE-2024-2004: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-2004
Component: CVE-2024-2004
apple
CVE-2025-43226P4MEDIUMCVSS 4.0v14.7.72025-07-29
CVE-2025-43226 [MEDIUM] CVE-2025-43226: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43226
Component: CVE-2025-43226
apple
CVE-2025-43205P4MEDIUMCVSS 4.0v14.7.52025-03-31
CVE-2025-43205 [MEDIUM] CVE-2025-43205: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-43205
Component: Audio
Impact: An app may be able to bypass ASLR
Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2023-42934P4MEDIUMCVSS 4.2v142023-09-26
CVE-2023-42934 [MEDIUM] CVE-2023-42934: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42934
Component: Photos Storage
Impact: An app with root privileges may be able to access private information
Description: An information disclosure issue was addressed by removing the vulnerable code.
apple
CVE-2025-43250P4MEDIUMCVSS 4.0v14.7.72025-07-29
CVE-2025-43250 [MEDIUM] CVE-2025-43250: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43250
Component: SharedFileList
Impact: An app may be able to break out of its sandbox
Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-43206P4MEDIUMCVSS 4.0v14.7.72025-07-29
CVE-2025-43206 [MEDIUM] CVE-2025-43206: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43206
Component: System Settings
Impact: An app may be able to access protected user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple