Apple Macos Tahoe vulnerabilities
322 known vulnerabilities affecting apple/macos_tahoe.
Total CVEs
322
CISA KEV
5
actively exploited
Public exploits
5
Exploited in wild
11
Severity breakdown
CRITICAL10HIGH82MEDIUM202LOW28
Vulnerabilities
Page 6 of 17
CVE-2026-20617P4HIGHCVSS 7.0v26.32026-02-11
CVE-2026-20617 [HIGH] CVE-2026-20617: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20617
Component: CoreServices
Impact: An app may be able to gain root privileges
Description: A race condition was addressed with improved state handling.
apple
CVE-2025-43511P4MEDIUMCVSS 6.5v26.22025-12-12
CVE-2025-43511 [MEDIUM] CVE-2025-43511: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-43511
Component: WebKit Web Inspector
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: A use-after-free issue was addressed with improved memory management.
apple
CVE-2025-43272P4MEDIUMCVSS 6.5v262025-09-15
CVE-2025-43272 [MEDIUM] CVE-2025-43272: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43272
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2025-43356P4MEDIUMCVSS 6.5v262025-09-15
CVE-2025-43356 [MEDIUM] CVE-2025-43356: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43356
Component: WebKit
Impact: A website may be able to access sensor information without user consent
Description: The issue was addressed with improved handling of caches.
apple
CVE-2025-43538P4MEDIUMCVSS 5.5v26.22025-12-12
CVE-2025-43538 [MEDIUM] CVE-2025-43538: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-43538
Component: Screen Time
Impact: An app may be able to access sensitive user data
Description: A logging issue was addressed with improved data redaction.
apple
CVE-2025-43440P4MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43440 [MEDIUM] CVE-2025-43440: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43440
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: This issue was addressed with improved checks
apple
CVE-2025-43327P4MEDIUMCVSS 6.5v262025-09-15
CVE-2025-43327 [MEDIUM] CVE-2025-43327: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43327
Component: Safari
Impact: Visiting a malicious website may lead to address bar spoofing
Description: The issue was addressed by adding additional logic.
apple
CVE-2026-20636P4MEDIUMCVSS 6.5v26.32026-02-11
CVE-2026-20636 [MEDIUM] CVE-2026-20636: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20636
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20644P4MEDIUMCVSS 6.5v26.32026-02-11
CVE-2026-20644 [MEDIUM] CVE-2026-20644: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20644
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20606P4HIGHCVSS 7.1v26.32026-02-11
CVE-2026-20606 [HIGH] CVE-2026-20606: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20606
Component: UIKit
Impact: An app may be able to bypass certain Privacy preferences
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2025-46298P4MEDIUMCVSS 6.5v26.22025-12-12
CVE-2025-46298 [MEDIUM] CVE-2025-46298: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2025-46298
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected process crash
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-43398P4MEDIUMCVSS 5.9v26.12025-11-03
CVE-2024-43398 [MEDIUM] CVE-2024-43398: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2024-43398
Component: CVE-2024-43398
apple
CVE-2025-43338P4HIGHCVSS 7.1v262025-09-15
CVE-2025-43338 [HIGH] CVE-2025-43338: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43338
Component: ImageIO
Impact: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory
Description: An out-of-bounds access issue was addressed with improved bounds checking.
apple
CVE-2025-43287P4HIGHCVSS 7.1v262025-09-15
CVE-2025-43287 [HIGH] CVE-2025-43287: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-43287
Component: ImageIO
Impact: Processing a maliciously crafted image may corrupt process memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2026-20641P4HIGHCVSS 7.1v26.32026-02-11
CVE-2026-20641 [HIGH] CVE-2026-20641: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20641
Component: StoreKit
Impact: An app may be able to identify what other apps a user has installed
Description: A privacy issue was addressed with improved checks.
apple
CVE-2026-20628P4HIGHCVSS 7.1v26.32026-02-11
CVE-2026-20628 [HIGH] CVE-2026-20628: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20628
Component: Sandbox
Impact: An app may be able to break out of its sandbox
Description: A permissions issue was addressed with additional restrictions.
apple
CVE-2025-43464P4MEDIUMCVSS 6.5v26.12025-11-03
CVE-2025-43464 [MEDIUM] CVE-2025-43464: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43464
Component: Dock
Impact: An app may be able to access sensitive user data
Description: A race condition was addressed with improved state handling.
apple
CVE-2026-20680P4MEDIUMCVSS 6.5v26.32026-02-11
CVE-2026-20680 [MEDIUM] CVE-2026-20680: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20680
Component: Spotlight
Impact: A sandboxed app may be able to access sensitive user data
Description: The issue was addressed with additional restrictions on the observability of app states.
apple
CVE-2025-43448P4MEDIUMCVSS 6.3v26.12025-11-03
CVE-2025-43448 [MEDIUM] CVE-2025-43448: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43448
Component: CloudKit
Impact: An app may be able to break out of its sandbox
Description: This issue was addressed with improved validation of symlinks.
apple
CVE-2025-43412P4MEDIUMCVSS 6.3v26.12025-11-03
CVE-2025-43412 [MEDIUM] CVE-2025-43412: macOS Tahoe 26.1
Apple Security Update: About the security content of macOS Tahoe 26.1
Product: macOS Tahoe
Version: 26.1
CVE: CVE-2025-43412
Component: TCC
Impact: An app may be able to break out of its sandbox
Description: A file quarantine bypass was addressed with additional checks.
apple