Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 6 of 48
CVE-2025-24119P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-24119 [HIGH] CVE-2025-24119: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-24119
Component: Finder
Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges
Description: This issue was addressed through improved state management.
apple
CVE-2025-46285P3HIGHCVSS 7.8v14.8.32025-12-12
CVE-2025-46285 [HIGH] CVE-2025-46285: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-46285
Component: Kernel
Impact: An app may be able to gain root privileges
Description: An integer overflow was addressed by adopting 64-bit timestamps.
apple
CVE-2024-40771P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-40771 [HIGH] CVE-2024-40771: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-40771
Component: AVEVideoEncoder
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-31183P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-31183 [CRITICAL] CVE-2025-31183: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-31183
Component: Siri
Impact: An app may be able to access sensitive user data
Description: The issue was addressed with improved restriction of data container access.
apple
CVE-2025-31221P3HIGHCVSS 7.5v14.7.62025-05-12
CVE-2025-31221 [HIGH] CVE-2025-31221: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31221
Component: Security
Impact: A remote attacker may be able to leak memory
Description: An integer overflow was addressed with improved input validation.
apple
CVE-2025-43186P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43186 [CRITICAL] CVE-2025-43186: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43186
Component: Admin Framework
Impact: An app may be able to cause a denial-of-service
Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-24206P3HIGHCVSS 7.7v14.7.52025-03-31
CVE-2025-24206 [HIGH] CVE-2025-24206: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24206
Component: AirPlay
Impact: An attacker on the local network may be able to bypass authentication policy
Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-24232P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24232 [CRITICAL] CVE-2025-24232: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24232
Component: NSDocument
Impact: A malicious app may be able to access arbitrary files
Description: This issue was addressed through improved state management.
apple
CVE-2025-24266P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24266 [CRITICAL] CVE-2025-24266: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24266
Component: Xsan
Impact: An app may be able to cause unexpected system termination
Description: A buffer overflow was addressed with improved bounds checking.
apple
CVE-2025-24273P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24273 [CRITICAL] CVE-2025-24273: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24273
Component: GPU Drivers
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-30444P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30444 [CRITICAL] CVE-2025-30444: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30444
Component: SMB
Impact: Mounting a maliciously crafted SMB network share may lead to system termination
Description: A race condition was addressed with improved locking.
apple
CVE-2025-43245P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43245 [CRITICAL] CVE-2025-43245: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43245
Component: AppleMobileFileIntegrity
Impact: An app may be able to access protected user data
Description: A downgrade issue was addressed with additional code-signing restrictions.
apple
CVE-2025-43198P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43198 [CRITICAL] CVE-2025-43198: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43198
Component: Dock
Impact: An app may be able to access protected user data
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43192P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43192 [CRITICAL] CVE-2025-43192: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43192
Component: Managed Configuration
Impact: Account-driven User Enrollment may still be possible with Lockdown Mode turned on
Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2024-44206P3CRITICALCVSS 9.3v14.62024-07-29
CVE-2024-44206 [CRITICAL] CVE-2024-44206: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2024-44206
Component: WebKit
Impact: A user may be able to bypass some web content restrictions
Description: An issue in the handling of URL protocols was addressed with improved logic.
apple
CVE-2026-20677P3CRITICALCVSS 9.0v14.8.42026-02-11
CVE-2026-20677 [CRITICAL] CVE-2026-20677: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20677
Component: Messages
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A race condition was addressed with improved handling of symbolic links.
apple
CVE-2024-27855P3HIGHCVSS 8.8v14.52024-05-13
CVE-2024-27855 [HIGH] CVE-2024-27855: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27855
Component: Shortcuts
Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user
Description: The issue was addressed with improved checks.
apple
CVE-2024-44122P3HIGHCVSS 8.8v14.7.12024-10-28
CVE-2024-44122 [HIGH] CVE-2024-44122: macOS Sonoma 14.7.1
Apple Security Update: About the security content of macOS Sonoma 14.7.1
Product: macOS Sonoma
Version: 14.7.1
CVE: CVE-2024-44122
Component: LaunchServices
Impact: An application may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-23208P3HIGHCVSS 7.8v14.32024-01-22
CVE-2024-23208 [HIGH] CVE-2024-23208: macOS Sonoma 14.3
Apple Security Update: About the security content of macOS Sonoma 14.3
Product: macOS Sonoma
Version: 14.3
CVE: CVE-2024-23208
Component: Kernel
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-42931P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42931 [HIGH] CVE-2023-42931: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42931
Component: DiskArbitration
Impact: A process may gain admin privileges without proper authentication
Description: The issue was addressed with improved checks.
apple