Apple Macos Tahoe vulnerabilities
322 known vulnerabilities affecting apple/macos_tahoe.
Total CVEs
322
CISA KEV
5
actively exploited
Public exploits
5
Exploited in wild
11
Severity breakdown
CRITICAL10HIGH82MEDIUM202LOW28
Vulnerabilities
Page 2 of 17
CVE-2025-43347P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-43347 [CRITICAL] CVE-2025-43347: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43347
Component: System
Impact: An input validation issue was addressed
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43526P3CRITICALCVSS 9.8v26.22025-12-12
CVE-2025-43526 [CRITICAL] CVE-2025-43526: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-43526
Component: Safari
Impact: On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted
Description: This issue was addressed with improved URL validation.
apple
CVE-2025-43342P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-43342 [CRITICAL] CVE-2025-43342: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43342
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A correctness issue was addressed with improved checks.
apple
CVE-2026-20616P3HIGHCVSS 8.8v26.32026-02-11
CVE-2026-20616 [HIGH] CVE-2026-20616: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20616
Component: Model I/O
Impact: Processing a maliciously crafted USD file may lead to unexpected app termination
Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-43359P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-43359 [CRITICAL] CVE-2025-43359: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43359
Component: Kernel
Impact: A UDP server socket bound to a local interface may become bound to all interfaces
Description: A logic issue was addressed with improved state management.
apple
CVE-2026-20660P3HIGHCVSS 7.5v26.32026-02-11
CVE-2026-20660 [HIGH] CVE-2026-20660: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20660
Component: CFNetwork
Impact: A remote user may be able to write arbitrary files
Description: A path handling issue was addressed with improved logic.
apple
CVE-2025-43358P3HIGHCVSS 8.8v262025-09-15
CVE-2025-43358 [HIGH] CVE-2025-43358: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43358
Component: Shortcuts
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2024-7264P3MEDIUMCVSS 6.5v26.22025-12-12
CVE-2024-7264 [MEDIUM] CVE-2024-7264: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2024-7264
Component: CVE-2024-7264
apple
CVE-2025-31255P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-31255 [CRITICAL] CVE-2025-31255: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-31255
Component: IOKit
Impact: An app may be able to access sensitive user data
Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-43400P3MEDIUMCVSS 6.3v26.0.12025-09-29
CVE-2025-43400 [MEDIUM] CVE-2025-43400: macOS Tahoe 26.0.1
Apple Security Update: About the security content of macOS Tahoe 26.0.1
Product: macOS Tahoe
Version: 26.0.1
CVE: CVE-2025-43400
Component: FontParser
Impact: Processing a maliciously crafted font may lead to unexpected app termination or corrupt process memory
Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-43524P3HIGHCVSS 8.8fixed in 26.22026-05-12
CVE-2025-43524 [HIGH] CWE-284 CVE-2025-43524: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
nvd
CVE-2025-46285P3HIGHCVSS 7.8v26.22025-12-12
CVE-2025-46285 [HIGH] CVE-2025-46285: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-46285
Component: Kernel
Impact: An app may be able to gain root privileges
Description: An integer overflow was addressed by adopting 64-bit timestamps.
apple
CVE-2025-43376P3HIGHCVSS 7.5v262025-09-15
CVE-2025-43376 [HIGH] CVE-2025-43376: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43376
Component: WebKit
Impact: A remote attacker may be able to view leaked DNS queries with Private Relay turned on
Description: A logic issue was addressed with improved state management.
apple
CVE-2026-20677P3CRITICALCVSS 9.0v26.32026-02-11
CVE-2026-20677 [CRITICAL] CVE-2026-20677: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20677
Component: Messages
Impact: A shortcut may be able to bypass sandbox restrictions
Description: A race condition was addressed with improved handling of symbolic links.
apple
CVE-2025-43329P3HIGHCVSS 8.8v262025-09-15
CVE-2025-43329 [HIGH] CVE-2025-43329: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43329
Component: Sandbox
Impact: An app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-46281P3HIGHCVSS 8.8v26.22025-12-12
CVE-2025-46281 [HIGH] CVE-2025-46281: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-46281
Component: File Bookmark
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-9086P3HIGHCVSS 7.5v26.22025-12-12
CVE-2025-9086 [HIGH] CVE-2025-9086: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-9086
Component: CVE-2025-9086
apple
CVE-2025-59375P3HIGHCVSS 7.5v26.32026-02-11
CVE-2025-59375 [HIGH] CVE-2025-59375: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2025-59375
Component: CVE-2025-59375
Impact: An app may be able to break out of its sandbox
Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43298P3HIGHCVSS 7.8v262025-09-15
CVE-2025-43298 [HIGH] CVE-2025-43298: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43298
Component: PackageKit
Impact: An app may be able to gain root privileges
Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2026-20614P3HIGHCVSS 7.8v26.32026-02-11
CVE-2026-20614 [HIGH] CVE-2026-20614: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20614
Component: Remote Management
Impact: An app may be able to gain root privileges
Description: A path handling issue was addressed with improved validation.
apple