VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2026-3598
RustDesk Server Generates Config Strings Using Reversible Encoding (Base64 + Reverse) Instead of Encryption
Published 2026-03-05 · Analyzed
8.7EPSS 0.003
CVE-2025-43257
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.
Published 2026-04-02 · Analyzed
8.7EPSS 0.002
CVE-2024-2398
HTTP/2 push headers memory-leak
Published 2024-03-27 · Analyzed
8.6EPSS 0.361
CVE-2023-28206
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Published 2023-04-10 · Analyzed
8.6KEVEPSS 0.232
CVE-2023-32409
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.
Published 2023-06-23 · Analyzed
8.6KEVEPSS 0.165
CVE-2021-21006
Heap buffer overflow when handling crafted font file could lead to arbitrary code execution
Published 2021-01-13 · Modified
8.6EPSS 0.056
CVE-2026-34621
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Published 2026-04-11 · Analyzed
8.6KEVEPSS 0.022
CVE-2023-40448
The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.
Published 2023-09-26 · Modified
8.6EPSS 0.022
CVE-2021-30975
This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious OSAX scripting addition may bypass Gatekeeper checks and circumvent sandbox restrictions.
Published 2021-08-24 · Modified
8.6EPSS 0.018
CVE-2023-23531
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Published 2023-02-27 · Modified
8.6EPSS 0.018
CVE-2021-30864
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A sandboxed process may be able to circumvent sandbox restrictions.
Published 2021-08-24 · Modified
8.6EPSS 0.014
CVE-2026-21267
Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Published 2026-01-13 · Analyzed
8.6EPSS 0.008
CVE-2023-32364
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.5. A sandboxed process may be able to circumvent sandbox restrictions.
Published 2023-07-27 · Modified
8.6EPSS 0.008
CVE-2024-23246
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to break out of its sandbox.
Published 2024-03-08 · Modified
8.6EPSS 0.007
CVE-2026-34622
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Published 2026-04-14 · Analyzed
8.6EPSS 0.007
CVE-2026-34689
Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-09-22 · Analyzed
8.6EPSS 0.007
CVE-2024-44270
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A sandboxed process may be able to circumvent sandbox restrictions.
Published 2024-10-28 · Modified
8.6EPSS 0.006
CVE-2022-32890
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.
Published 2022-11-01 · Modified
8.6EPSS 0.006
CVE-2022-32892
An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.
Published 2022-11-01 · Modified
8.6EPSS 0.006
CVE-2024-23278
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, watchOS 10.4. An app may be able to break out of its sandbox.
Published 2024-03-08 · Modified
8.6EPSS 0.005
CVE-2026-43760
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.
Published 2026-07-27 · Modified
8.6EPSS 0.004
CVE-2024-27813
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Published 2024-05-13 · Modified
8.6EPSS 0.004
CVE-2022-42843
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
Published 2022-12-15 · Modified
8.6EPSS 0.004
CVE-2026-48350
Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Published 2026-07-14 · Analyzed
8.6EPSS 0.003
CVE-2026-47906
Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
Published 2026-06-09 · Analyzed
8.6EPSS 0.003
CVE-2026-76199
Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)
Published 2026-09-08 · Analyzed
8.6EPSS 0.003
CVE-2026-19305
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components
Published 2026-09-04 · Analyzed
8.6EPSS 0.003
CVE-2026-47907
Dreamweaver Desktop | Improper Access Control (CWE-284)
Published 2026-06-09 · Analyzed
8.6EPSS 0.003
CVE-2023-23530
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Published 2023-02-27 · Modified
8.6EPSS 0.003
CVE-2024-0258
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Published 2024-03-08 · Modified
8.6EPSS 0.003
CVE-2023-42947
A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.
Published 2024-03-28 · Modified
8.6EPSS 0.003
CVE-2026-21280
Illustrator | Untrusted Search Path (CWE-426)
Published 2026-01-13 · Analyzed
8.6EPSS 0.003
CVE-2024-54514
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to break out of its sandbox.
Published 2024-12-11 · Modified
8.6EPSS 0.003
CVE-2026-21268
Dreamweaver Desktop | Improper Input Validation (CWE-20)
Published 2026-01-13 · Analyzed
8.6EPSS 0.002
CVE-2026-21271
Dreamweaver Desktop | Improper Input Validation (CWE-20)
Published 2026-01-13 · Analyzed
8.6EPSS 0.002
CVE-2024-23299
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to break out of its sandbox.
Published 2024-06-10 · Modified
8.6EPSS 0.002
CVE-2022-46720
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to break out of its sandbox
Published 2023-05-08 · Modified
8.6EPSS 0.002
CVE-2026-21272
Dreamweaver Desktop | Improper Input Validation (CWE-20)
Published 2026-01-13 · Analyzed
8.6EPSS 0.002
CVE-2023-42838
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Published 2024-02-21 · Modified
8.6EPSS 0.002
CVE-2023-27944
This issue was addressed with a new entitlement. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to break out of its sandbox.
Published 2023-05-08 · Modified
8.6EPSS 0.002
← Prev44 / 177Next →