cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 6 of 48
CVE-2025-24119P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-24119 [HIGH] CVE-2025-24119: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-24119 Component: Finder Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges Description: This issue was addressed through improved state management.
apple
CVE-2025-46285P3HIGHCVSS 7.8v14.8.32025-12-12
CVE-2025-46285 [HIGH] CVE-2025-46285: macOS Sonoma 14.8.3 Apple Security Update: About the security content of macOS Sonoma 14.8.3 Product: macOS Sonoma Version: 14.8.3 CVE: CVE-2025-46285 Component: Kernel Impact: An app may be able to gain root privileges Description: An integer overflow was addressed by adopting 64-bit timestamps.
apple
CVE-2024-40771P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-40771 [HIGH] CVE-2024-40771: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-40771 Component: AVEVideoEncoder Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling.
apple
CVE-2025-31183P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-31183 [CRITICAL] CVE-2025-31183: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-31183 Component: Siri Impact: An app may be able to access sensitive user data Description: The issue was addressed with improved restriction of data container access.
apple
CVE-2025-31221P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2025-31221 [HIGH] CVE-2025-31221: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-31221 Component: Security Impact: A remote attacker may be able to leak memory Description: An integer overflow was addressed with improved input validation.
apple
CVE-2025-43186P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43186 [CRITICAL] CVE-2025-43186: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43186 Component: Admin Framework Impact: An app may be able to cause a denial-of-service Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-24206P3HIGHCVSS 7.7v14.7.52025-03-31
CVE-2025-24206 [HIGH] CVE-2025-24206: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24206 Component: AirPlay Impact: An attacker on the local network may be able to bypass authentication policy Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-24232P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24232 [CRITICAL] CVE-2025-24232: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24232 Component: NSDocument Impact: A malicious app may be able to access arbitrary files Description: This issue was addressed through improved state management.
apple
CVE-2025-24266P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24266 [CRITICAL] CVE-2025-24266: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24266 Component: Xsan Impact: An app may be able to cause unexpected system termination Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2025-24273P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24273 [CRITICAL] CVE-2025-24273: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24273 Component: GPU Drivers Impact: An app may be able to cause unexpected system termination or corrupt kernel memory Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-30444P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30444 [CRITICAL] CVE-2025-30444: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-30444 Component: SMB Impact: Mounting a maliciously crafted SMB network share may lead to system termination Description: A race condition was addressed with improved locking.
apple
CVE-2025-43245P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43245 [CRITICAL] CVE-2025-43245: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43245 Component: AppleMobileFileIntegrity Impact: An app may be able to access protected user data Description: A downgrade issue was addressed with additional code-signing restrictions.
apple
CVE-2025-43198P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43198 [CRITICAL] CVE-2025-43198: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43198 Component: Dock Impact: An app may be able to access protected user data Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43192P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43192 [CRITICAL] CVE-2025-43192: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43192 Component: Managed Configuration Impact: Account-driven User Enrollment may still be possible with Lockdown Mode turned on Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2024-44206P3CRITICALCVSS 9.3v14.62024-07-29
CVE-2024-44206 [CRITICAL] CVE-2024-44206: macOS Sonoma 14.6 Apple Security Update: About the security content of macOS Sonoma 14.6 Product: macOS Sonoma Version: 14.6 CVE: CVE-2024-44206 Component: WebKit Impact: A user may be able to bypass some web content restrictions Description: An issue in the handling of URL protocols was addressed with improved logic.
apple
CVE-2026-20677P3CRITICALCVSS 9.0v14.8.42026-02-11
CVE-2026-20677 [CRITICAL] CVE-2026-20677: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20677 Component: Messages Impact: A shortcut may be able to bypass sandbox restrictions Description: A race condition was addressed with improved handling of symbolic links.
apple
CVE-2024-27855P3HIGHCVSS 8.8v14.52024-05-13
CVE-2024-27855 [HIGH] CVE-2024-27855: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27855 Component: Shortcuts Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user Description: The issue was addressed with improved checks.
apple
CVE-2024-44122P3HIGHCVSS 8.8v14.7.12024-10-28
CVE-2024-44122 [HIGH] CVE-2024-44122: macOS Sonoma 14.7.1 Apple Security Update: About the security content of macOS Sonoma 14.7.1 Product: macOS Sonoma Version: 14.7.1 CVE: CVE-2024-44122 Component: LaunchServices Impact: An application may be able to break out of its sandbox Description: A logic issue was addressed with improved checks.
apple
CVE-2024-23208P3HIGHCVSS 7.8v14.32024-01-22
CVE-2024-23208 [HIGH] CVE-2024-23208: macOS Sonoma 14.3 Apple Security Update: About the security content of macOS Sonoma 14.3 Product: macOS Sonoma Version: 14.3 CVE: CVE-2024-23208 Component: Kernel Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling.
apple
CVE-2023-42931P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42931 [HIGH] CVE-2023-42931: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42931 Component: DiskArbitration Impact: A process may gain admin privileges without proper authentication Description: The issue was addressed with improved checks.
apple
Apple Macos Sonoma vulnerabilities | cvebase