Apple Macos Tahoe vulnerabilities
322 known vulnerabilities affecting apple/macos_tahoe.
Total CVEs
322
CISA KEV
5
actively exploited
Public exploits
5
Exploited in wild
11
Severity breakdown
CRITICAL10HIGH82MEDIUM202LOW28
Vulnerabilities
Page 5 of 17
CVE-2025-43462P3HIGHCVSS 7.5v26.12025-11-03
CVE-2025-43462 [HIGH] CVE-2025-43462: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43462
Impact: An app may be able to cause unexpected system termination or corrupt kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43494P3HIGHCVSS 7.5v26.12025-11-03
CVE-2025-43494 [HIGH] CVE-2025-43494: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43494
Component: Mail
Impact: An attacker may be able to cause a persistent denial-of-service
Description: A mail header parsing issue was addressed with improved checks.
apple
CVE-2025-24088P3HIGHCVSS 7.5v262025-09-15
CVE-2025-24088 [HIGH] CVE-2025-24088: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-24088
Component: CoreServices
Impact: An app may be able to override MDM-enforced settings from profiles
Description: The issue was addressed by adding additional logic.
apple
CVE-2025-31271P3HIGHCVSS 7.5v262025-09-15
CVE-2025-31271 [HIGH] CVE-2025-31271: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-31271
Component: FaceTime
Impact: Incoming FaceTime calls can appear or be accepted on a locked macOS device, even with notifications disabled on the lock screen
Description: This issue was addressed through improved state management.
apple
CVE-2026-28855P3HIGHCVSS 7.5v26.32026-02-11
CVE-2026-28855 [HIGH] CVE-2026-28855: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-28855
Component: Screen Time
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43330P3HIGHCVSS 8.2v262025-09-15
CVE-2025-43330 [HIGH] CVE-2025-43330: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43330
Component: ATS
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43323P3HIGHCVSS 8.1v262025-09-15
CVE-2025-43323 [HIGH] CVE-2025-43323: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43323
Component: CloudKit
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with additional entitlement checks.
apple
CVE-2025-43333P3HIGHCVSS 7.8v262025-09-15
CVE-2025-43333 [HIGH] CVE-2025-43333: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43333
Component: Spotlight
Impact: An app may be able to gain root privileges
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43541P4MEDIUMCVSS 4.3v26.22025-12-12
CVE-2025-43541 [MEDIUM] CVE-2025-43541: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-43541
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A type confusion issue was addressed with improved state handling.
apple
CVE-2025-43204P3HIGHCVSS 7.8v262025-09-15
CVE-2025-43204 [HIGH] CVE-2025-43204: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43204
Component: RemoteViewServices
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-43476P3HIGHCVSS 7.8v26.12025-11-03
CVE-2025-43476 [HIGH] CVE-2025-43476: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43476
Component: SharedFileList
Impact: An app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43364P3HIGHCVSS 7.8v26.12025-11-03
CVE-2025-43364 [HIGH] CVE-2025-43364: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43364
Component: NetFSFramework
Impact: An app may be able to break out of its sandbox
Description: A race condition was addressed with additional validation.
apple
CVE-2025-43506P3HIGHCVSS 7.5v26.12025-11-03
CVE-2025-43506 [HIGH] CVE-2025-43506: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43506
Component: Networking
Impact: iCloud Private Relay may not activate when more than one user is logged in at the same time
Description: A logic error was addressed with improved error handling.
apple
CVE-2025-43407P3HIGHCVSS 7.8v26.12025-11-03
CVE-2025-43407 [HIGH] CVE-2025-43407: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43407
Component: Assets
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved entitlements.
apple
CVE-2025-43340P3HIGHCVSS 7.8v262025-09-15
CVE-2025-43340 [HIGH] CVE-2025-43340: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43340
Component: AppleMobileFileIntegrity
Impact: An app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-6442P3MEDIUMCVSS 5.9v26.12025-11-03
CVE-2025-6442 [MEDIUM] CVE-2025-6442: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-6442
Component: CVE-2025-6442
apple
CVE-2025-43457P4MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43457 [MEDIUM] CVE-2025-43457: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43457
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-46287P4MEDIUMCVSS 6.5v26.22025-12-12
CVE-2025-46287 [MEDIUM] CVE-2025-46287: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-46287
Component: Calling Framework
Impact: An attacker may be able to spoof their FaceTime caller ID
Description: An inconsistent user interface issue was addressed with improved state management.
apple
CVE-2025-43507P4MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43507 [MEDIUM] CVE-2025-43507: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43507
Component: Find My
Impact: An app may be able to fingerprint the user
Description: A privacy issue was addressed by moving sensitive data.
apple
CVE-2025-43304P4HIGHCVSS 7.0v262025-09-15
CVE-2025-43304 [HIGH] CVE-2025-43304: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43304
Component: StorageKit
Impact: An app may be able to gain root privileges
Description: A race condition was addressed with improved state handling.
apple