Apple Macos Tahoe vulnerabilities
321 known vulnerabilities affecting apple/macos_tahoe.
Total CVEs
321
CISA KEV
5
actively exploited
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH81MEDIUM202LOW28
Vulnerabilities
Page 11 of 17
CVE-2025-43463MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43463 [MEDIUM] CVE-2025-43463: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43463
Component: StorageKit
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-43446MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43446 [MEDIUM] CVE-2025-43446: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43446
Component: Assets
Impact: An app may be able to modify protected parts of the file system
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43448MEDIUMCVSS 6.3v26.12025-11-03
CVE-2025-43448 [MEDIUM] CVE-2025-43448: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43448
Component: CloudKit
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43390MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43390 [MEDIUM] CVE-2025-43390: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43390
Component: AppleMobileFileIntegrity
Impact: An app may be able to access user-sensitive data
Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
apple
CVE-2025-43468MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43468 [MEDIUM] CVE-2025-43468: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43468
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
apple
CVE-2025-43445MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43445 [MEDIUM] CVE-2025-43445: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43445
Component: CoreText
Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory
Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2025-43378MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43378 [MEDIUM] CVE-2025-43378: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43378
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43493MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43493 [MEDIUM] CVE-2025-43493: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43493
Component: Safari
Impact: Visiting a malicious website may lead to address bar spoofing
Description: The issue was addressed with improved checks.
apple
CVE-2025-43440MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43440 [MEDIUM] CVE-2025-43440: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43440
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: This issue was addressed with improved checks
apple
CVE-2025-43464MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43464 [MEDIUM] CVE-2025-43464: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43464
Component: Dock
Impact: An app may be able to access sensitive user data
Description: A race condition was addressed with improved state handling.
apple
CVE-2025-43507MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43507 [MEDIUM] CVE-2025-43507: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43507
Component: Find My
Impact: An app may be able to fingerprint the user
Description: A privacy issue was addressed by moving sensitive data.
apple
CVE-2025-43432MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43432 [MEDIUM] CVE-2025-43432: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43432
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-43498MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43498 [MEDIUM] CVE-2025-43498: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43498
Component: FileProvider
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2024-49761MEDIUMCVSS 6.6v26.12025-11-03
CVE-2024-49761 [MEDIUM] CVE-2024-49761: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2024-49761
Component: CVE-2024-49761
apple
CVE-2025-43382MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43382 [MEDIUM] CVE-2025-43382: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43382
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2025-43466MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43466 [MEDIUM] CVE-2025-43466: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43466
Component: AppleMobileFileIntegrity
Impact: An app may be able to access sensitive user data
Description: An injection issue was addressed with improved validation.
apple
CVE-2025-43471MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43471 [MEDIUM] CVE-2025-43471: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43471
Component: Admin Framework
Impact: An app may be able to access sensitive user data
Description: The issue was addressed with improved checks.
apple
CVE-2025-43520MEDIUMCVSS 5.5KEVv26.12025-11-03
CVE-2025-43520 [MEDIUM] CVE-2025-43520: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43520
Component: Kernel
Impact: A malicious application may be able to cause unexpected system termination or write kernel memory
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2025-43406MEDIUMCVSS 5.5v26.12025-11-03
CVE-2025-43406 [MEDIUM] CVE-2025-43406: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43406
Component: Sandbox
Impact: An app may be able to access sensitive user data
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2025-43414MEDIUMCVSS 6.2v26.12025-11-03
CVE-2025-43414 [MEDIUM] CVE-2025-43414: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43414
Component: Shortcuts
Impact: A shortcut may be able to access files that are normally inaccessible to the Shortcuts app
Description: A permissions issue was addressed with improved validation.
apple