Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 7 of 48
CVE-2024-27856P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27856 [HIGH] CVE-2024-27856: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
apple
CVE-2025-9086P3HIGHCVSS 7.5v14.8.32025-12-12
CVE-2025-9086 [HIGH] CVE-2025-9086: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2025-9086
Component: CVE-2025-9086
apple
CVE-2023-40455P3CRITICALCVSS 10.0v142023-09-26
CVE-2023-40455 [CRITICAL] CVE-2023-40455: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40455
Component: NetFSFramework
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2023-38586P3CRITICALCVSS 10.0v142023-09-26
CVE-2023-38586 [CRITICAL] CVE-2023-38586: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-38586
Component: Image Capture
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: An access issue was addressed with additional sandbox restrictions.
apple
CVE-2025-59375P3HIGHCVSS 7.5v14.8.42026-02-11
CVE-2025-59375 [HIGH] CVE-2025-59375: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An attacker in a privileged network position may be able to intercept network traffic
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-23278P3HIGHCVSS 7.8v14.42024-03-07
CVE-2024-23278 [HIGH] CVE-2024-23278: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23278
Component: CVE-2024-23225
Impact: A maliciously crafted ZIP archive may bypass Gatekeeper checks
Description: This issue was addressed with improved checks.
apple
CVE-2023-40423P3HIGHCVSS 7.8v14.12023-10-25
CVE-2023-40423 [HIGH] CVE-2023-40423: macOS Sonoma 14.1
Apple Security Update: About the security content of macOS Sonoma 14.1
Product: macOS Sonoma
Version: 14.1
CVE: CVE-2023-40423
Component: IOTextEncryptionFamily
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-42899P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42899 [HIGH] CVE-2023-42899: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42899
Component: ImageIO
Impact: Processing an image may lead to arbitrary code execution
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-27802P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27802 [HIGH] CVE-2024-27802: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27802
Component: Metal
Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2024-27836P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27836 [HIGH] CVE-2024-27836: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27836
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: The issue was addressed with improved checks.
apple
CVE-2025-43196P3HIGHCVSS 7.8v14.7.72025-07-29
CVE-2025-43196 [HIGH] CVE-2025-43196: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43196
Component: LaunchServices
Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges
Description: This issue was addressed through improved state management.
apple
CVE-2025-43298P3HIGHCVSS 7.8v14.82025-09-15
CVE-2025-43298 [HIGH] CVE-2025-43298: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43298
Component: PackageKit
Impact: An app may be able to gain root privileges
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2023-40396P3HIGHCVSS 7.8v142023-09-26
CVE-2023-40396 [HIGH] CVE-2023-40396: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40396
Component: IOUserEthernet
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-24274P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-24274 [HIGH] CVE-2025-24274: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-24274
Component: Mobile Device Service
Impact: A malicious app may be able to gain root privileges
Description: An input validation issue was addressed by removing the vulnerable code.
apple
CVE-2026-20614P3HIGHCVSS 7.8v14.8.42026-02-11
CVE-2026-20614 [HIGH] CVE-2026-20614: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20614
Component: Remote Management
Impact: An app may be able to gain root privileges
Description: A path handling issue was addressed with improved validation.
apple
CVE-2026-20615P3HIGHCVSS 7.8v14.8.42026-02-11
CVE-2026-20615 [HIGH] CVE-2026-20615: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20615
Component: CoreServices
Impact: An app may be able to gain root privileges
Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-43413P3HIGHCVSS 7.5v14.8.22025-11-03
CVE-2025-43413 [HIGH] CVE-2025-43413: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43413
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2025-43405P3HIGHCVSS 7.5v14.8.22025-11-03
CVE-2025-43405 [HIGH] CVE-2025-43405: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43405
Component: Photos
Impact: An app may be able to access user-sensitive data
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2025-43273P3CRITICALCVSS 9.1v14.82025-09-15
CVE-2025-43273 [CRITICAL] CVE-2025-43273: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-43273
Component: CoreMedia
Impact: A sandboxed process may be able to circumvent sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2024-23246P3HIGHCVSS 8.6v14.42024-03-07
CVE-2024-23246 [HIGH] CVE-2024-23246: macOS Sonoma 14.4
Apple Security Update: About the security content of macOS Sonoma 14.4
Product: macOS Sonoma
Version: 14.4
CVE: CVE-2024-23246
Component: UIKit
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed by removing the vulnerable code.
apple