Apple Macos Sonoma vulnerabilities
959 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
959
CISA KEV
11
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL73HIGH289MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 5 of 48
CVE-2025-43397MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43397 [MEDIUM] CVE-2025-43397: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43397
Component: SoftwareUpdate
Impact: An app may be able to cause a denial-of-service
Description: A permissions issue was addressed by removing the vulnerable code.
apple
CVE-2025-43478MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43478 [MEDIUM] CVE-2025-43478: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43478
Component: ASP TCP
Impact: An app may be able to cause unexpected system termination
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2025-43348MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43348 [MEDIUM] CVE-2025-43348: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43348
Component: Finder
Impact: An app may bypass Gatekeeper checks
Description: A logic issue was addressed with improved validation.
apple
CVE-2025-43420MEDIUMCVSS 4.7v14.8.22025-11-03
CVE-2025-43420 [MEDIUM] CVE-2025-43420: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43420
Component: Dock
Impact: An app may be able to access sensitive user data
Description: A race condition was addressed with improved state handling.
apple
CVE-2025-43396MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43396 [MEDIUM] CVE-2025-43396: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43396
Component: Installer
Impact: A sandboxed app may be able to access sensitive user data
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43414MEDIUMCVSS 6.2v14.8.22025-11-03
CVE-2025-43414 [MEDIUM] CVE-2025-43414: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43414
Component: Shortcuts
Impact: A shortcut may be able to access files that are normally inaccessible to the Shortcuts app
Description: A permissions issue was addressed with improved validation.
apple
CVE-2025-43499MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43499 [MEDIUM] CVE-2025-43499: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43499
Component: Shortcuts
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2024-43398MEDIUMCVSS 5.9v14.8.22025-11-03
CVE-2024-43398 [MEDIUM] CVE-2024-43398: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2024-43398
Component: CVE-2024-43398
apple
CVE-2025-43411MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43411 [MEDIUM] CVE-2025-43411: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43411
Component: PackageKit
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2025-43498MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43498 [MEDIUM] CVE-2025-43498: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43498
Component: FileProvider
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-43335MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43335 [MEDIUM] CVE-2025-43335: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43335
Component: Security
Impact: An app may be able to access user-sensitive data
Description: The issue was addressed by adding additional logic.
apple
CVE-2025-43334MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43334 [MEDIUM] CVE-2025-43334: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43334
Component: Spotlight
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-43380MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43380 [MEDIUM] CVE-2025-43380: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43380
Component: Shortcuts
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2025-43446MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43446 [MEDIUM] CVE-2025-43446: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43446
Component: Assets
Impact: An app may be able to modify protected parts of the file system
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43479MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43479 [MEDIUM] CVE-2025-43479: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43479
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43322MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43322 [MEDIUM] CVE-2025-43322: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43322
Component: Admin Framework
Impact: An app may be able to access user-sensitive data
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-49761MEDIUMCVSS 6.6v14.8.22025-11-03
CVE-2024-49761 [MEDIUM] CVE-2024-49761: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2024-49761
Component: CVE-2024-49761
apple
CVE-2025-43448MEDIUMCVSS 6.3v14.8.22025-11-03
CVE-2025-43448 [MEDIUM] CVE-2025-43448: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43448
Component: CloudKit
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43469MEDIUMCVSS 5.5v14.8.22025-11-03
CVE-2025-43469 [MEDIUM] CVE-2025-43469: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43469
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43520MEDIUMCVSS 5.5KEVv14.8.22025-11-03
CVE-2025-43520 [MEDIUM] CVE-2025-43520: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
apple