cbcvebase.

Apple Macos Tahoe vulnerabilities

322 known vulnerabilities affecting apple/macos_tahoe.

Total CVEs
322
CISA KEV
5
actively exploited
Public exploits
5
Exploited in wild
11
Severity breakdown
CRITICAL10HIGH82MEDIUM202LOW28

Vulnerabilities

Page 2 of 17
CVE-2025-43347P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-43347 [CRITICAL] CVE-2025-43347: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43347 Component: System Impact: An input validation issue was addressed Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43526P3CRITICALCVSS 9.8v26.22025-12-12
CVE-2025-43526 [CRITICAL] CVE-2025-43526: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2025-43526 Component: Safari Impact: On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted Description: This issue was addressed with improved URL validation.
apple
CVE-2025-43342P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-43342 [CRITICAL] CVE-2025-43342: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43342 Component: WebKit Impact: Processing maliciously crafted web content may lead to an unexpected process crash Description: A correctness issue was addressed with improved checks.
apple
CVE-2026-20616P3HIGHCVSS 8.8v26.32026-02-11
CVE-2026-20616 [HIGH] CVE-2026-20616: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20616 Component: Model I/O Impact: Processing a maliciously crafted USD file may lead to unexpected app termination Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-43359P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-43359 [CRITICAL] CVE-2025-43359: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43359 Component: Kernel Impact: A UDP server socket bound to a local interface may become bound to all interfaces Description: A logic issue was addressed with improved state management.
apple
CVE-2026-20660P3HIGHCVSS 7.5v26.32026-02-11
CVE-2026-20660 [HIGH] CVE-2026-20660: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20660 Component: CFNetwork Impact: A remote user may be able to write arbitrary files Description: A path handling issue was addressed with improved logic.
apple
CVE-2025-43358P3HIGHCVSS 8.8v262025-09-15
CVE-2025-43358 [HIGH] CVE-2025-43358: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43358 Component: Shortcuts Impact: A shortcut may be able to bypass sandbox restrictions Description: A permissions issue was addressed with additional sandbox restrictions.
apple
CVE-2024-7264P3MEDIUMCVSS 6.5v26.22025-12-12
CVE-2024-7264 [MEDIUM] CVE-2024-7264: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2024-7264 Component: CVE-2024-7264
apple
CVE-2025-31255P3CRITICALCVSS 9.8v262025-09-15
CVE-2025-31255 [CRITICAL] CVE-2025-31255: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-31255 Component: IOKit Impact: An app may be able to access sensitive user data Description: An authorization issue was addressed with improved state management.
apple
CVE-2025-43400P3MEDIUMCVSS 6.3v26.0.12025-09-29
CVE-2025-43400 [MEDIUM] CVE-2025-43400: macOS Tahoe 26.0.1 Apple Security Update: About the security content of macOS Tahoe 26.0.1 Product: macOS Tahoe Version: 26.0.1 CVE: CVE-2025-43400 Component: FontParser Impact: Processing a maliciously crafted font may lead to unexpected app termination or corrupt process memory Description: An out-of-bounds write issue was addressed with improved bounds checking.
apple
CVE-2025-43524P3HIGHCVSS 8.8fixed in 26.22026-05-12
CVE-2025-43524 [HIGH] CWE-284 CVE-2025-43524: An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
nvd
CVE-2025-46285P3HIGHCVSS 7.8v26.22025-12-12
CVE-2025-46285 [HIGH] CVE-2025-46285: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2025-46285 Component: Kernel Impact: An app may be able to gain root privileges Description: An integer overflow was addressed by adopting 64-bit timestamps.
apple
CVE-2025-43376P3HIGHCVSS 7.5v262025-09-15
CVE-2025-43376 [HIGH] CVE-2025-43376: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43376 Component: WebKit Impact: A remote attacker may be able to view leaked DNS queries with Private Relay turned on Description: A logic issue was addressed with improved state management.
apple
CVE-2026-20677P3CRITICALCVSS 9.0v26.32026-02-11
CVE-2026-20677 [CRITICAL] CVE-2026-20677: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20677 Component: Messages Impact: A shortcut may be able to bypass sandbox restrictions Description: A race condition was addressed with improved handling of symbolic links.
apple
CVE-2025-43329P3HIGHCVSS 8.8v262025-09-15
CVE-2025-43329 [HIGH] CVE-2025-43329: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43329 Component: Sandbox Impact: An app may be able to break out of its sandbox Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-46281P3HIGHCVSS 8.8v26.22025-12-12
CVE-2025-46281 [HIGH] CVE-2025-46281: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2025-46281 Component: File Bookmark Impact: An app may be able to break out of its sandbox Description: A logic issue was addressed with improved checks.
apple
CVE-2025-9086P3HIGHCVSS 7.5v26.22025-12-12
CVE-2025-9086 [HIGH] CVE-2025-9086: macOS Tahoe 26.2 Apple Security Update: About the security content of macOS Tahoe 26.2 Product: macOS Tahoe Version: 26.2 CVE: CVE-2025-9086 Component: CVE-2025-9086
apple
CVE-2025-59375P3HIGHCVSS 7.5v26.32026-02-11
CVE-2025-59375 [HIGH] CVE-2025-59375: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2025-59375 Component: CVE-2025-59375 Impact: An app may be able to break out of its sandbox Description: A logic issue was addressed with improved checks.
apple
CVE-2025-43298P3HIGHCVSS 7.8v262025-09-15
CVE-2025-43298 [HIGH] CVE-2025-43298: macOS Tahoe 26 Apple Security Update: About the security content of macOS Tahoe 26 Product: macOS Tahoe Version: 26 CVE: CVE-2025-43298 Component: PackageKit Impact: An app may be able to gain root privileges Description: A parsing issue in the handling of directory paths was addressed with improved path validation.
apple
CVE-2026-20614P3HIGHCVSS 7.8v26.32026-02-11
CVE-2026-20614 [HIGH] CVE-2026-20614: macOS Tahoe 26.3 Apple Security Update: About the security content of macOS Tahoe 26.3 Product: macOS Tahoe Version: 26.3 CVE: CVE-2026-20614 Component: Remote Management Impact: An app may be able to gain root privileges Description: A path handling issue was addressed with improved validation.
apple
Apple Macos Tahoe vulnerabilities | cvebase