VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2023-46689
Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2024-05-16 · Analyzed
8.8EPSS 0.002
CVE-2026-11670
Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11306
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-12020
Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-11 · Analyzed
8.8EPSS 0.002
CVE-2025-52841
Laundry 2.3.0 - Account Takeover via CSRF
Published 2025-07-02 · Analyzed
8.8EPSS 0.002
CVE-2026-24070
Local Privilege Escalation via DYLIB Injection in Native Instruments Native Access
Published 2026-02-02 · Modified
8.8EPSS 0.002
CVE-2026-11079
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory write via a crafted video file. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2025-43270
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may gain unauthorized access to Local Network.
Published 2025-07-29 · Modified
8.8EPSS 0.002
CVE-2026-11301
Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11201
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2025-6426
No warning when opening executable terminal files on macOS
Published 2025-06-24 · Modified
8.8EPSS 0.002
CVE-2025-46281
A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.2. An app may be able to break out of its sandbox.
Published 2025-12-17 · Modified
8.8EPSS 0.002
CVE-2026-11699
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11698
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11687
Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-6406
Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2026-3063
Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)
Published 2026-02-23 · Modified
8.8EPSS 0.002
CVE-2023-40070
Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2024-05-16 · Analyzed
8.8EPSS 0.002
CVE-2023-40398
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.4, macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A sandboxed process may be able to circumvent sandbox restrictions.
Published 2024-07-29 · Modified
8.8EPSS 0.002
CVE-2026-10019
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-28 · Modified
8.8EPSS 0.002
CVE-2025-31244
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.
Published 2025-05-12 · Modified
8.8EPSS 0.002
CVE-2026-10926
Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11304
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-5817
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2026-5843
Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2026-10002
Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Published 2026-05-28 · Modified
8.8EPSS 0.002
CVE-2026-11092
Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-28923
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.
Published 2026-05-11 · Analyzed
8.8EPSS 0.002
CVE-2026-84578
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
Published 2026-09-14 · Analyzed
8.8EPSS 0.002
CVE-2026-28978
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.
Published 2026-05-11 · Analyzed
8.8EPSS 0.002
CVE-2026-28995
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A malicious app may be able to break out of its sandbox.
Published 2026-05-11 · Modified
8.8EPSS 0.002
CVE-2025-1095
IBM Personal Communications command execution
Published 2025-04-08 · Modified
8.8EPSS 0.001
CVE-2026-20667
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
Published 2026-02-11 · Modified
8.8EPSS 0.001
CVE-2025-24284
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.
Published 2026-06-11 · Analyzed
8.8EPSS 0.001
CVE-2025-43524
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
Published 2026-05-12 · Analyzed
8.8EPSS 0.001
CVE-2022-50890
Owlfiles File Manager 12.0.1 - Path Traversal
Published 2026-01-13 · Analyzed
8.7EPSS 0.011
CVE-2026-34617
Adobe Connect | Cross-site Scripting (XSS) (CWE-79)
Published 2026-04-14 · Analyzed
8.7EPSS 0.007
CVE-2026-35562
Allocation of resources without limits in parsing components in Amazon Athena ODBC driver
Published 2026-04-03 · Analyzed
8.7EPSS 0.007
CVE-2026-30791
RustDesk Client Accepts Pseudo-Encrypted Config Strings Without Cryptographic Validation
Published 2026-03-05 · Analyzed
8.7EPSS 0.003
CVE-2026-30795
RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure
Published 2026-03-05 · Analyzed
8.7EPSS 0.003
← Prev43 / 177Next →