VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2026-24178
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
Published 2026-04-28 · Analyzed
9.8EPSS 0.006
CVE-2026-64703
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.
Published 2026-07-27 · Analyzed
9.8EPSS 0.006
CVE-2026-64746
An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.
Published 2026-07-27 · Modified
9.8EPSS 0.006
CVE-2026-64738
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
Published 2026-07-27 · Modified
9.8EPSS 0.006
CVE-2026-28982
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
Published 2026-07-27 · Analyzed
9.8EPSS 0.006
CVE-2026-43779
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to intercept network connections intended for another process.
Published 2026-07-27 · Analyzed
9.8EPSS 0.005
CVE-2026-64702
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.
Published 2026-07-27 · Analyzed
9.8EPSS 0.005
CVE-2025-43526
This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content opened via a file URL may be able to use Web APIs that should be restricted.
Published 2025-12-17 · Modified
9.8EPSS 0.005
CVE-2025-43237
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected system termination.
Published 2025-07-29 · Modified
9.8EPSS 0.005
CVE-2025-23360
NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering.
Published 2025-03-11 · Analyzed
9.8EPSS 0.005
CVE-2026-9258
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.005
CVE-2025-24109
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access sensitive user data.
Published 2025-01-27 · Modified
9.8EPSS 0.005
CVE-2026-28911
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.
Published 2026-07-27 · Analyzed
9.8EPSS 0.005
CVE-2026-64727
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.
Published 2026-07-27 · Analyzed
9.8EPSS 0.005
CVE-2025-24263
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.4. An app may be able to observe unprotected user data.
Published 2025-03-31 · Analyzed
9.8EPSS 0.005
CVE-2025-46287
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. An attacker may be able to spoof their FaceTime caller ID.
Published 2025-12-12 · Modified
9.8EPSS 0.005
CVE-2026-64691
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
Published 2026-07-27 · Analyzed
9.8EPSS 0.005
CVE-2026-64720
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
Published 2026-07-27 · Analyzed
9.8EPSS 0.005
CVE-2026-43805
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
Published 2026-07-27 · Analyzed
9.8EPSS 0.005
CVE-2026-30783
RustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
Published 2026-03-05 · Modified
9.8EPSS 0.005
CVE-2026-84520
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.
Published 2026-09-14 · Analyzed
9.8EPSS 0.004
CVE-2024-27841
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.
Published 2024-05-13 · Modified
9.8EPSS 0.004
CVE-2026-9260
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.004
CVE-2025-43416
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may be able to access protected user data.
Published 2025-12-12 · Modified
9.8EPSS 0.004
CVE-2025-14917
IBM WebSphere Application Server Liberty could provide weaker than expected security
Published 2026-03-25 · Analyzed
9.8EPSS 0.004
CVE-2023-44077
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
Published 2024-01-17 · Modified
9.8EPSS 0.004
CVE-2026-13446
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Analyzed
9.8EPSS 0.004
CVE-2026-3062
Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-02-23 · Modified
9.8EPSS 0.004
CVE-2023-0834
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 before 8.1.
Published 2023-04-28 · Modified
9.8EPSS 0.004
CVE-2025-46279
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.
Published 2025-12-17 · Modified
9.8EPSS 0.004
CVE-2026-13776
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
CVE-2026-0906
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Published 2026-01-20 · Analyzed
9.8EPSS 0.003
CVE-2026-9259
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.003
CVE-2026-30793
RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
Published 2026-03-05 · Analyzed
9.8EPSS 0.003
CVE-2026-5902
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Analyzed
9.8EPSS 0.003
CVE-2026-30789
RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
Published 2026-03-05 · Modified
9.8EPSS 0.003
CVE-2026-9261
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published 2026-06-15 · Analyzed
9.8EPSS 0.003
CVE-2026-13775
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
CVE-2025-30466
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.
Published 2025-05-29 · Modified
9.8EPSS 0.003
CVE-2026-47304
.NET Security Feature Bypass Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.003
← Prev12 / 177Next →