cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 5 of 48
CVE-2025-43270P3HIGHCVSS 8.8v14.7.72025-07-29
CVE-2025-43270 [HIGH] CVE-2025-43270: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43270 Component: Notes Impact: An app may gain unauthorized access to Local Network Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2024-0258P3HIGHCVSS 8.6v14.42024-03-07
CVE-2024-0258 [HIGH] CVE-2024-0258: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-0258 Component: CVE-2024-23225 Impact: A maliciously crafted ZIP archive may bypass Gatekeeper checks Description: This issue was addressed with improved checks.
apple
CVE-2024-7264P3MEDIUMCVSS 6.5v14.8.32025-12-12
CVE-2024-7264 [MEDIUM] CVE-2024-7264: macOS Sonoma 14.8.3 Apple Security Update: About the security content of macOS Sonoma 14.8.3 Product: macOS Sonoma Version: 14.8.3 CVE: CVE-2024-7264 Component: CVE-2024-7264
apple
CVE-2024-23286P3HIGHCVSS 7.8v14.42024-03-07
CVE-2024-23286 [HIGH] CVE-2024-23286: macOS Sonoma 14.4 Apple Security Update: About the security content of macOS Sonoma 14.4 Product: macOS Sonoma Version: 14.4 CVE: CVE-2024-23286 Component: ImageIO Impact: Processing an image may lead to arbitrary code execution Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2025-31255P3CRITICALCVSS 9.8v14.82025-09-15
CVE-2025-31255 [CRITICAL] CVE-2025-31255: macOS Sonoma 14.8 Apple Security Update: About the security content of macOS Sonoma 14.8 Product: macOS Sonoma Version: 14.8 CVE: CVE-2025-31255 Component: IOKit Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management.
apple
CVE-2024-27831P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27831 [HIGH] CVE-2024-27831: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27831 Component: CoreMedia Impact: Processing a file may lead to unexpected app termination or arbitrary code execution Description: An out-of-bounds write issue was addressed with improved input validation.
apple
CVE-2025-43199P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43199 [CRITICAL] CVE-2025-43199: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43199 Component: CoreServices Impact: A malicious app may be able to gain root privileges Description: A permissions issue was addressed by removing the vulnerable code.
apple
CVE-2023-42875P3HIGHCVSS 7.3v142023-09-26
CVE-2023-42875 [HIGH] CVE-2023-42875: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-42875 Component: WebKit Impact: Processing web content may lead to arbitrary code execution Description: The issue was addressed with improved memory handling.
apple
CVE-2024-44270P3HIGHCVSS 8.6v14.7.12024-10-28
CVE-2024-44270 [HIGH] CVE-2024-44270: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44270 Component: AppleMobileFileIntegrity Impact: A sandboxed process may be able to circumvent sandbox restrictions Description: A logic issue was addressed with improved validation.
apple
CVE-2025-43400P3MEDIUMCVSS 6.3v14.8.12025-09-29
CVE-2025-43400 [MEDIUM] CVE-2025-43400: macOS Sonoma 14.8.1 Apple Security Update: About the security content of macOS Sonoma 14.8.1 Product: macOS Sonoma Version: 14.8.1 CVE: CVE-2025-43400 Component: FontParser Impact: Processing a maliciously crafted font may lead to unexpected app termination or corrupt process memory Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-43524P3HIGHCVSS 8.8fixed in 14.8.72026-05-12
CVE-2025-43524 [HIGH] CWE-284 CVE-2025-43524: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
nvd
CVE-2024-27813P3HIGHCVSS 8.6v14.52024-05-13
CVE-2024-27813 [HIGH] CVE-2024-27813: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27813 Component: PrintCenter Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges Description: The issue was addressed with improved checks.
apple
CVE-2023-42838P3HIGHCVSS 8.6v14.12023-10-25
CVE-2023-42838 [HIGH] CVE-2023-42838: macOS Sonoma 14.1 Apple Security Update: About the security content of macOS Sonoma 14.1 Product: macOS Sonoma Version: 14.1 CVE: CVE-2023-42838 Component: Pro Res Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved bounds checks.
apple
CVE-2024-27857P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27857 [HIGH] CVE-2024-27857: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27857 Component: Metal Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2025-24178P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24178 [HIGH] CVE-2025-24178: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24178 Component: CVE-2024-56171 Impact: An app may be able to break out of its sandbox Description: This issue was addressed through improved state management.
apple
CVE-2025-31182P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-31182 [HIGH] CVE-2025-31182: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-31182 Component: CVE-2024-56171 Impact: An app may be able to break out of its sandbox Description: This issue was addressed through improved state management.
apple
CVE-2024-23204P3HIGHCVSS 7.5v14.32024-01-22
CVE-2024-23204 [HIGH] CVE-2024-23204: macOS Sonoma 14.3 Apple Security Update: About the security content of macOS Sonoma 14.3 Product: macOS Sonoma Version: 14.3 CVE: CVE-2024-23204 Component: Shortcuts Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user Description: The issue was addressed with additional permissions checks.
apple
CVE-2024-8176P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2024-8176 [HIGH] CVE-2024-8176: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2024-8176 Component: CVE-2024-8176
apple
CVE-2025-24243P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24243 [HIGH] CVE-2025-24243: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24243 Component: Audio Impact: Processing a maliciously crafted file may lead to arbitrary code execution Description: The issue was addressed with improved memory handling.
apple
CVE-2023-41984P3HIGHCVSS 7.8v142023-09-26
CVE-2023-41984 [HIGH] CVE-2023-41984: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-41984 Component: Kernel Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling.
apple
Apple Macos Sonoma vulnerabilities | cvebase