Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 5 of 48
CVE-2025-43270P3HIGHCVSS 8.8v14.7.72025-07-29
CVE-2025-43270 [HIGH] CVE-2025-43270: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43270
Component: Notes
Impact: An app may gain unauthorized access to Local Network
Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2024-0258P3HIGHCVSS 8.6v14.42024-03-07
CVE-2024-0258 [HIGH] CVE-2024-0258: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-0258
Component: CVE-2024-23225
Impact: A maliciously crafted ZIP archive may bypass Gatekeeper checks
Description: This issue was addressed with improved checks.
apple
CVE-2024-7264P3MEDIUMCVSS 6.5v14.8.32025-12-12
CVE-2024-7264 [MEDIUM] CVE-2024-7264: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2024-7264
Component: CVE-2024-7264
apple
CVE-2024-23286P3HIGHCVSS 7.8v14.42024-03-07
CVE-2024-23286 [HIGH] CVE-2024-23286: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23286
Component: ImageIO
Impact: Processing an image may lead to arbitrary code execution
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2025-31255P3CRITICALCVSS 9.8v14.82025-09-15
CVE-2025-31255 [CRITICAL] CVE-2025-31255: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-31255
Component: IOKit
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2024-27831P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27831 [HIGH] CVE-2024-27831: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27831
Component: CoreMedia
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved input validation.
apple
CVE-2025-43199P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43199 [CRITICAL] CVE-2025-43199: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43199
Component: CoreServices
Impact: A malicious app may be able to gain root privileges
Description: A permissions issue was addressed by removing the vulnerable code.
apple
CVE-2023-42875P3HIGHCVSS 7.3v142023-09-26
CVE-2023-42875 [HIGH] CVE-2023-42875: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42875
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-44270P3HIGHCVSS 8.6v14.7.12024-10-28
CVE-2024-44270 [HIGH] CVE-2024-44270: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44270
Component: AppleMobileFileIntegrity
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: A logic issue was addressed with improved validation.
apple
CVE-2025-43400P3MEDIUMCVSS 6.3v14.8.12025-09-29
CVE-2025-43400 [MEDIUM] CVE-2025-43400: macOS Sonoma 14.8.1
Apple Security Update: About the security content of macOS Sonoma 14.8.1
Product: macOS Sonoma
Version: 14.8.1
CVE: CVE-2025-43400
Component: FontParser
Impact: Processing a maliciously crafted font may lead to unexpected app termination or corrupt process memory
Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-43524P3HIGHCVSS 8.8fixed in 14.8.72026-05-12
CVE-2025-43524 [HIGH] CWE-284 CVE-2025-43524: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
nvd
CVE-2024-27813P3HIGHCVSS 8.6v14.52024-05-13
CVE-2024-27813 [HIGH] CVE-2024-27813: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27813
Component: PrintCenter
Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges
Description: The issue was addressed with improved checks.
apple
CVE-2023-42838P3HIGHCVSS 8.6v14.12023-10-25
CVE-2023-42838 [HIGH] CVE-2023-42838: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-42838
Component: Pro Res
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved bounds checks.
apple
CVE-2024-27857P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27857 [HIGH] CVE-2024-27857: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27857
Component: Metal
Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution
Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2025-24178P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24178 [HIGH] CVE-2025-24178: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24178
Component: CVE-2024-56171
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed through improved state management.
apple
CVE-2025-31182P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-31182 [HIGH] CVE-2025-31182: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31182
Component: CVE-2024-56171
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed through improved state management.
apple
CVE-2024-23204P3HIGHCVSS 7.5v14.32024-01-22
CVE-2024-23204 [HIGH] CVE-2024-23204: macOS Sonoma 14.3
Apple Security Update: About the security content of macOS Sonoma 14.3
Product: macOS Sonoma
Version: 14.3
CVE: CVE-2024-23204
Component: Shortcuts
Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user
Description: The issue was addressed with additional permissions checks.
apple
CVE-2024-8176P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2024-8176 [HIGH] CVE-2024-8176: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2024-8176
Component: CVE-2024-8176
apple
CVE-2025-24243P3HIGHCVSS 7.8v14.7.52025-03-31
CVE-2025-24243 [HIGH] CVE-2025-24243: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24243
Component: Audio
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-41984P3HIGHCVSS 7.8v142023-09-26
CVE-2023-41984 [HIGH] CVE-2023-41984: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-41984
Component: Kernel
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
apple