cbcvebase.

Apple Macos Sonoma vulnerabilities

960 known vulnerabilities affecting apple/macos_sonoma.

Total CVEs
960
CISA KEV
11
actively exploited
Public exploits
8
Exploited in wild
19
Severity breakdown
CRITICAL73HIGH290MEDIUM533LOW63UNKNOWN1

Vulnerabilities

Page 9 of 48
CVE-2025-31222P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-31222 [HIGH] CVE-2025-31222: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-31222 Component: Libinfo Impact: An app may be able to bypass ASLR Description: The issue was addressed with improved checks.
apple
CVE-2023-42892P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42892 [HIGH] CVE-2023-42892: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42892 Component: FileURL Impact: A local attacker may be able to elevate their privileges Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2024-27817P3HIGHCVSS 7.8v14.52024-05-13
CVE-2024-27817 [HIGH] CVE-2024-27817: macOS Sonoma 14.5 Apple Security Update: About the security content of macOS Sonoma 14.5 Product: macOS Sonoma Version: 14.5 CVE: CVE-2024-27817 Component: CoreMedia Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved checks.
apple
CVE-2025-43472P3HIGHCVSS 7.8v14.8.22025-11-03
CVE-2025-43472 [HIGH] CVE-2025-43472: macOS Sonoma 14.8.2 Apple Security Update: About the security content of macOS Sonoma 14.8.2 Product: macOS Sonoma Version: 14.8.2 CVE: CVE-2025-43472 Component: Audio Impact: A malicious app may be able to read kernel memory Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2025-30453P3HIGHCVSS 7.8v14.7.62025-05-12
CVE-2025-30453 [HIGH] CVE-2025-30453: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-30453 Component: DiskArbitration Impact: A malicious app may be able to gain root privileges Description: The issue was addressed with additional permissions checks.
apple
CVE-2025-46290P3HIGHCVSS 7.5v14.8.42026-02-11
CVE-2025-46290 [HIGH] CVE-2025-46290: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2025-46290 Component: Security Impact: A remote attacker may be able to cause a denial-of-service Description: A logic issue was addressed with improved checks.
apple
CVE-2025-31213P3HIGHCVSS 7.6v14.7.62025-05-12
CVE-2025-31213 [HIGH] CVE-2025-31213: macOS Sonoma 14.7.6 Apple Security Update: About the security content of macOS Sonoma 14.7.6 Product: macOS Sonoma Version: 14.7.6 CVE: CVE-2025-31213 Component: Security Impact: An app may be able to access associated usernames and websites in a user's iCloud Keychain Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-24246P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24246 [CRITICAL] CVE-2025-24246: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24246 Component: OpenSSH Impact: An app may be able to access user-sensitive data Description: An injection issue was addressed with improved validation.
apple
CVE-2025-24250P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24250 [CRITICAL] CVE-2025-24250: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24250 Component: Security Impact: A malicious app acting as a HTTPS proxy could get access to sensitive user data Description: This issue was addressed with improved access restrictions.
apple
CVE-2025-24260P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-24260 [CRITICAL] CVE-2025-24260: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24260 Component: SMB Impact: An app may be able to execute arbitrary code with kernel privileges Description: A buffer overflow issue was addressed with improved memory handling.
apple
CVE-2023-40393P3HIGHCVSS 7.5v142023-09-26
CVE-2023-40393 [HIGH] CVE-2023-40393: macOS Sonoma 14 Apple Security Update: About the security content of macOS Sonoma 14 Product: macOS Sonoma Version: 14 CVE: CVE-2023-40393 Component: Photos Impact: Photos in the Hidden Photos Album may be viewed without authentication Description: An authentication issue was addressed with improved state management.
apple
CVE-2025-30462P3CRITICALCVSS 9.8v14.7.52025-03-31
CVE-2025-30462 [CRITICAL] CVE-2025-30462: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-30462 Component: Dock Impact: An app may be able to modify protected parts of the file system Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43222P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43222 [CRITICAL] CVE-2025-43222: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43222 Component: CFNetwork Impact: An attacker may be able to cause unexpected app termination Description: A use-after-free issue was addressed by removing the vulnerable code.
apple
CVE-2025-43232P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43232 [CRITICAL] CVE-2025-43232: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43232 Component: PackageKit Impact: An app may be able to bypass certain Privacy preferences Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43233P3CRITICALCVSS 9.8v14.7.72025-07-29
CVE-2025-43233 [CRITICAL] CVE-2025-43233: macOS Sonoma 14.7.7 Apple Security Update: About the security content of macOS Sonoma 14.7.7 Product: macOS Sonoma Version: 14.7.7 CVE: CVE-2025-43233 Component: Security Impact: A malicious app acting as a HTTPS proxy could get access to sensitive user data Description: This issue was addressed with improved access restrictions.
apple
CVE-2025-30460P3HIGHCVSS 7.4v14.7.52025-03-31
CVE-2025-30460 [HIGH] CVE-2025-30460: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-30460 Component: Automator Impact: An app may be able to access protected user data Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
apple
CVE-2026-20667P3HIGHCVSS 7.5v14.8.42026-02-11
CVE-2026-20667 [HIGH] CVE-2026-20667: macOS Sonoma 14.8.4 Apple Security Update: About the security content of macOS Sonoma 14.8.4 Product: macOS Sonoma Version: 14.8.4 CVE: CVE-2026-20667 Component: CVE-2025-59375 Impact: An attacker in a privileged network position may be able to intercept network traffic Description: A logic issue was addressed with improved checks.
apple
CVE-2023-42947P3HIGHCVSS 8.6v14.22023-12-11
CVE-2023-42947 [HIGH] CVE-2023-42947: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42947 Component: TCC Impact: An app may be able to break out of its sandbox Description: A path handling issue was addressed with improved validation.
apple
CVE-2025-24255P3HIGHCVSS 8.4v14.7.52025-03-31
CVE-2025-24255 [HIGH] CVE-2025-24255: macOS Sonoma 14.7.5 Apple Security Update: About the security content of macOS Sonoma 14.7.5 Product: macOS Sonoma Version: 14.7.5 CVE: CVE-2025-24255 Component: Disk Images Impact: An app may be able to break out of its sandbox Description: A file access issue was addressed with improved input validation.
apple
CVE-2023-42906P3HIGHCVSS 7.8v14.22023-12-11
CVE-2023-42906 [HIGH] CVE-2023-42906: macOS Sonoma 14.2 Apple Security Update: About the security content of macOS Sonoma 14.2 Product: macOS Sonoma Version: 14.2 CVE: CVE-2023-42906 Component: AppleGraphicsControl Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution Description: Multiple memory corruption issues were addressed with improved input validation.
apple
Apple Macos Sonoma vulnerabilities | cvebase