Apple Macos Tahoe vulnerabilities

321 known vulnerabilities affecting apple/macos_tahoe.

Total CVEs
321
CISA KEV
5
actively exploited
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH81MEDIUM202LOW28

Vulnerabilities

Page 11 of 17
CVE-2025-43463MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43463 [MEDIUM] CVE-2025-43463: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43463 Component: StorageKit Impact: An app may be able to access sensitive user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-43446MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43446 [MEDIUM] CVE-2025-43446: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43446 Component: Assets Impact: An app may be able to modify protected parts of the file system Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43448MEDIUMCVSS 6.3v26.12025-11-03
CVE-2025-43448 [MEDIUM] CVE-2025-43448: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43448 Component: CloudKit Impact: An app may be able to break out of its sandbox Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43390MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43390 [MEDIUM] CVE-2025-43390: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43390 Component: AppleMobileFileIntegrity Impact: An app may be able to access user-sensitive data Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
apple
CVE-2025-43468MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43468 [MEDIUM] CVE-2025-43468: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43468 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
apple
CVE-2025-43445MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43445 [MEDIUM] CVE-2025-43445: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43445 Component: CoreText Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2025-43378MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43378 [MEDIUM] CVE-2025-43378: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43378 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43493MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43493 [MEDIUM] CVE-2025-43493: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43493 Component: Safari Impact: Visiting a malicious website may lead to address bar spoofing Description: The issue was addressed with improved checks.
apple
CVE-2025-43440MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43440 [MEDIUM] CVE-2025-43440: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43440 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: This issue was addressed with improved checks
apple
CVE-2025-43464MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43464 [MEDIUM] CVE-2025-43464: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43464 Component: Dock Impact: An app may be able to access sensitive user data Description: A race condition was addressed with improved state handling.
apple
CVE-2025-43507MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43507 [MEDIUM] CVE-2025-43507: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43507 Component: Find My Impact: An app may be able to fingerprint the user Description: A privacy issue was addressed by moving sensitive data.
apple
CVE-2025-43432MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43432 [MEDIUM] CVE-2025-43432: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43432 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-43498MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43498 [MEDIUM] CVE-2025-43498: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43498 Component: FileProvider Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management.
apple
CVE-2024-49761MEDIUMCVSS 6.6v26.12025-11-03
CVE-2024-49761 [MEDIUM] CVE-2024-49761: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2024-49761 Component: CVE-2024-49761
apple
CVE-2025-43382MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43382 [MEDIUM] CVE-2025-43382: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43382 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-43466MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43466 [MEDIUM] CVE-2025-43466: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43466 Component: AppleMobileFileIntegrity Impact: An app may be able to access sensitive user data Description: An injection issue was addressed with improved validation.
apple
CVE-2025-43471MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43471 [MEDIUM] CVE-2025-43471: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43471 Component: Admin Framework Impact: An app may be able to access sensitive user data Description: The issue was addressed with improved checks.
apple
CVE-2025-43520MEDIUMCVSS 5.5KEVv26.12025-11-03
CVE-2025-43520 [MEDIUM] CVE-2025-43520: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43520 Component: Kernel Impact: A malicious application may be able to cause unexpected system termination or write kernel memory Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2025-43406MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43406 [MEDIUM] CVE-2025-43406: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43406 Component: Sandbox Impact: An app may be able to access sensitive user data Description: A logic issue was addressed with improved restrictions.
apple
CVE-2025-43414MEDIUMCVSS 6.2v26.12025-11-03
CVE-2025-43414 [MEDIUM] CVE-2025-43414: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43414 Component: Shortcuts Impact: A shortcut may be able to access files that are normally inaccessible to the Shortcuts app Description: A permissions issue was addressed with improved validation.
apple