Apple Macos Sonoma vulnerabilities
960 known vulnerabilities affecting apple/macos_sonoma.
Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1
Vulnerabilities
Page 9 of 48
CVE-2025-31222P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-31222 [HIGH] CVE-2025-31222: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31222
Component: Libinfo
Impact: An app may be able to bypass ASLR
Description: The issue was addressed with improved checks.
apple
CVE-2023-42892P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42892 [HIGH] CVE-2023-42892: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42892
Component: FileURL
Impact: A local attacker may be able to elevate their privileges
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2024-27817P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27817 [HIGH] CVE-2024-27817: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27817
Component: CoreMedia
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved checks.
apple
CVE-2025-43472P3HIGHCVSS 7.8v14.8.22025-11-03
CVE-2025-43472 [HIGH] CVE-2025-43472: macOS Sonoma 14.8.2
Apple Security Update: About the security content of macOS Sonoma 14.8.2
Product: macOS Sonoma
Version: 14.8.2
CVE: CVE-2025-43472
Component: Audio
Impact: A malicious app may be able to read kernel memory
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2025-30453P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-30453 [HIGH] CVE-2025-30453: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-30453
Component: DiskArbitration
Impact: A malicious app may be able to gain root privileges
Description: The issue was addressed with additional permissions checks.
apple
CVE-2025-46290P3HIGHCVSS 7.5v14.8.42026-02-11
CVE-2025-46290 [HIGH] CVE-2025-46290: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2025-46290
Component: Security
Impact: A remote attacker may be able to cause a denial-of-service
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-31213P3HIGHCVSS 7.6v14.7.62025-05-12
CVE-2025-31213 [HIGH] CVE-2025-31213: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-31213
Component: Security
Impact: An app may be able to access associated usernames and websites in a user's iCloud Keychain
Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-24246P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24246 [CRITICAL] CVE-2025-24246: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24246
Component: OpenSSH
Impact: An app may be able to access user-sensitive data
Description: An injection issue was addressed with improved validation.
apple
CVE-2025-24250P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24250 [CRITICAL] CVE-2025-24250: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24250
Component: Security
Impact: A malicious app acting as a HTTPS proxy could get access to sensitive user data
Description: This issue was addressed with improved access restrictions.
apple
CVE-2025-24260P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24260 [CRITICAL] CVE-2025-24260: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24260
Component: SMB
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2023-40393P3HIGHCVSS 7.5v142023-09-26
CVE-2023-40393 [HIGH] CVE-2023-40393: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40393
Component: Photos
Impact: Photos in the Hidden Photos Album may be viewed without authentication
Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-30462P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30462 [CRITICAL] CVE-2025-30462: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30462
Component: Dock
Impact: An app may be able to modify protected parts of the file system
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43222P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43222 [CRITICAL] CVE-2025-43222: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43222
Component: CFNetwork
Impact: An attacker may be able to cause unexpected app termination
Description: A use-after-free issue was addressed by removing the vulnerable code.
apple
CVE-2025-43232P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43232 [CRITICAL] CVE-2025-43232: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43232
Component: PackageKit
Impact: An app may be able to bypass certain Privacy preferences
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43233P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43233 [CRITICAL] CVE-2025-43233: macOS Sonoma 14.7.7
Apple Security Update: About the security content of macOS Sonoma 14.7.7
Product: macOS Sonoma
Version: 14.7.7
CVE: CVE-2025-43233
Component: Security
Impact: A malicious app acting as a HTTPS proxy could get access to sensitive user data
Description: This issue was addressed with improved access restrictions.
apple
CVE-2025-30460P3HIGHCVSS 7.4v14.7.52025-03-31
CVE-2025-30460 [HIGH] CVE-2025-30460: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-30460
Component: Automator
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
apple
CVE-2026-20667P3HIGHCVSS 7.5v14.8.42026-02-11
CVE-2026-20667 [HIGH] CVE-2026-20667: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20667
Component: CVE-2025-59375
Impact: An attacker in a privileged network position may be able to intercept network traffic
Description: A logic issue was addressed with improved checks.
apple
CVE-2023-42947P3HIGHCVSS 8.6v14.22023-12-11
CVE-2023-42947 [HIGH] CVE-2023-42947: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42947
Component: TCC
Impact: An app may be able to break out of its sandbox
Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-24255P3HIGHCVSS 8.4v14.7.52025-03-31
CVE-2025-24255 [HIGH] CVE-2025-24255: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2025-24255
Component: Disk Images
Impact: An app may be able to break out of its sandbox
Description: A file access issue was addressed with improved input validation.
apple
CVE-2023-42906P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42906 [HIGH] CVE-2023-42906: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-42906
Component: AppleGraphicsControl
Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
apple