cbcvebase.

Apple Macos Tahoe vulnerabilities

322 known vulnerabilities affecting apple/macos_tahoe.

Total CVEs
322
CISA KEV
5
actively exploited
Public exploits
5
Exploited in wild
11
Severity breakdown
CRITICAL10HIGH82MEDIUM202LOW28

Vulnerabilities

Page 15 of 17
CVE-2026-20602P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20602 [MEDIUM] CVE-2026-20602: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20602 Component: WindowServer Impact: An app may be able to cause a denial-of-service Description: The issue was addressed with improved handling of caches.
apple
CVE-2026-20654P4MEDIUMCVSS 5.5v26.32026-02-11
CVE-2026-20654 [MEDIUM] CVE-2026-20654: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20654 Component: Kernel Impact: An app may be able to cause unexpected system termination Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43262P4MEDIUMCVSS 5.1v262025-09-15
CVE-2025-43262 [MEDIUM] CVE-2025-43262: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43262 Component: Trusted Device Impact: USB Restricted Mode may not be applied to accessories connected during boot Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43421P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43421 [MEDIUM] CVE-2025-43421: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43421 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: Multiple issues were addressed by disabling array allocation sinking.
apple
CVE-2025-43503P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43503 [MEDIUM] CVE-2025-43503: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43503 Component: Safari Impact: Visiting a malicious website may lead to user interface spoofing Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2025-46316P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-46316 [MEDIUM] CVE-2025-46316: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-46316 Component: QuickLook Impact: Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory Description: An out-of-bounds read was addressed with improved input validation.
apple
CVE-2025-43355P4MEDIUMCVSS 5.5v262025-09-15
CVE-2025-43355 [MEDIUM] CVE-2025-43355: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43355 Component: MobileStorageMounter Impact: An app may be able to cause a denial-of-service Description: A type confusion issue was addressed with improved memory handling.
apple
CVE-2025-43392P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43392 [MEDIUM] CVE-2025-43392: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43392 Component: WebKit Canvas Impact: A website may exfiltrate image data cross-origin Description: The issue was addressed with improved handling of caches.
apple
CVE-2025-43336P4MEDIUMCVSS 4.4v26.12025-11-03
CVE-2025-43336 [MEDIUM] CVE-2025-43336: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43336 Component: SoftwareUpdate Impact: An app with root privileges may be able to access private information Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2024-8906P4MEDIUMCVSS 4.3v26.22025-12-12
CVE-2024-8906 [MEDIUM] CVE-2024-8906: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2024-8906 Component: Safari Downloads Impact: A download's origin may be incorrectly associated Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2025-43493P4MEDIUMCVSS 4.3v26.12025-11-03
CVE-2025-43493 [MEDIUM] CVE-2025-43493: macOS Tahoe 26.1 Apple Security Update: About the security content of macOS Tahoe 26.1 Product: macOS Tahoe Version: 26.1 CVE: CVE-2025-43493 Component: Safari Impact: Visiting a malicious website may lead to address bar spoofing Description: The issue was addressed with improved checks.
apple
CVE-2025-46299P4MEDIUMCVSS 4.3v26.22025-12-12
CVE-2025-46299 [MEDIUM] CVE-2025-46299: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2025-46299 Component: WebKit Impact: Processing maliciously crafted web content may disclose internal states of the app Description: A memory initialization issue was addressed with improved memory handling.
apple
CVE-2026-20662P4MEDIUMCVSS 4.6v26.32026-02-11
CVE-2026-20662 [MEDIUM] CVE-2026-20662: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20662 Component: Siri Impact: An attacker with physical access to a locked device may be able to view sensitive user information Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-43310P4MEDIUMCVSS 4.4v262025-09-15
CVE-2025-43310 [MEDIUM] CVE-2025-43310: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43310 Component: WindowServer Impact: An app may be able to trick a user into copying sensitive data to the pasteboard Description: A configuration issue was addressed with additional restrictions.
apple
CVE-2026-20603P4MEDIUMCVSS 4.4v26.32026-02-11
CVE-2026-20603 [MEDIUM] CVE-2026-20603: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20603 Component: Notification Center Impact: An app with root privileges may be able to access private information Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2026-20609P4MEDIUMCVSS 4.4v26.32026-02-11
CVE-2026-20609 [MEDIUM] CVE-2026-20609: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20609 Component: CoreMedia Impact: Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43331P4MEDIUMCVSS 4.0v262025-09-15
CVE-2025-43331 [MEDIUM] CVE-2025-43331: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43331 Component: AppleMobileFileIntegrity Impact: An app may be able to access protected user data Description: A downgrade issue was addressed with additional code-signing restrictions.
apple
CVE-2026-20605P4MEDIUMCVSS 4.6v26.32026-02-11
CVE-2026-20605 [MEDIUM] CVE-2026-20605: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20605 Component: Voice Control Impact: An app may be able to crash a system process Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43307P4MEDIUMCVSS 4.0v262025-09-15
CVE-2025-43307 [MEDIUM] CVE-2025-43307: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43307 Component: Bluetooth Impact: An app may be able to access sensitive user data Description: This issue was addressed with improved checks to prevent unauthorized actions.
apple
CVE-2025-43531P4LOWCVSS 3.1v26.22025-12-12
CVE-2025-43531 [LOW] CVE-2025-43531: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2025-43531 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A race condition was addressed with improved state handling.
apple
Apple Macos Tahoe vulnerabilities | cvebase