VendorsApplemacosany version
Vulnerabilities

Apple MACOS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7030CVEs
CVE-2025-34190
Vasion Print (formerly PrinterLogic) PrinterInstallerClientService Authentication Bypass via LD_PRELOAD Hooking
Published 2025-09-19 · Modified
8.5EPSS 0.004
CVE-2025-34191
Vasion Print (formerly PrinterLogic) Arbitrary File Write as Root via Response Path Symlink Follow
Published 2025-09-19 · Modified
8.5EPSS 0.003
CVE-2025-10751
MacForge 1.2.0 Beta 1 - Local Privilege Escalation
Published 2025-10-04 · Analyzed
8.5EPSS 0.002
CVE-2026-45175
Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes
Published 2026-06-11 · Analyzed
8.5EPSS 0.002
CVE-2022-0572
Heap-based Buffer Overflow in vim/vim
Published 2022-02-13 · Modified
8.4EPSS 0.265
CVE-2022-0714
Heap-based Buffer Overflow in vim/vim
Published 2022-02-22 · Modified
8.4EPSS 0.127
CVE-2022-0629
Stack-based Buffer Overflow in vim/vim
Published 2022-02-17 · Modified
8.4EPSS 0.019
CVE-2022-0685
Use of Out-of-range Pointer Offset in vim/vim
Published 2022-02-20 · Modified
8.4EPSS 0.017
CVE-2022-0554
Use of Out-of-range Pointer Offset in vim/vim
Published 2022-02-10 · Modified
8.4EPSS 0.017
CVE-2022-0361
Heap-based Buffer Overflow in vim/vim
Published 2022-01-26 · Modified
8.4EPSS 0.016
CVE-2022-0943
Heap-based Buffer Overflow occurs in vim in vim/vim
Published 2022-03-14 · Modified
8.4EPSS 0.007
CVE-2022-0351
Access of Memory Location Before Start of Buffer in vim/vim
Published 2022-01-25 · Modified
8.4EPSS 0.006
CVE-2025-59489
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.
Published 2025-10-03 · Analyzed
8.4EPSS 0.006
CVE-2024-23274
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
Published 2024-03-08 · Modified
8.4EPSS 0.004
CVE-2024-23268
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
Published 2024-03-08 · Modified
8.4EPSS 0.004
CVE-2024-27801
The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.
Published 2024-06-10 · Modified
8.4EPSS 0.004
CVE-2024-40800
An input validation issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.
Published 2024-07-29 · Modified
8.4EPSS 0.003
CVE-2024-44255
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to run arbitrary shortcuts without user consent.
Published 2024-10-28 · Modified
8.4EPSS 0.003
CVE-2025-34188
Vasion Print (formerly PrinterLogic) Local Log Disclosure of Cleartext Sessions
Published 2025-09-19 · Modified
8.4EPSS 0.003
CVE-2024-23276
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
Published 2024-03-08 · Modified
8.4EPSS 0.003
CVE-2025-24255
A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.
Published 2025-03-31 · Modified
8.4EPSS 0.003
CVE-2021-44719
Docker Desktop 4.3.0 has Incorrect Access Control.
Published 2022-05-25 · Modified
8.4EPSS 0.003
CVE-2024-23288
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to elevate privileges.
Published 2024-03-08 · Modified
8.4EPSS 0.003
CVE-2024-40828
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious app may be able to gain root privileges.
Published 2024-07-29 · Modified
8.4EPSS 0.003
CVE-2024-40781
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to elevate their privileges.
Published 2024-07-29 · Modified
8.4EPSS 0.002
CVE-2024-40821
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.
Published 2024-07-29 · Modified
8.4EPSS 0.002
CVE-2024-40811
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system.
Published 2024-07-29 · Modified
8.4EPSS 0.002
CVE-2026-84581
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
Published 2026-09-14 · Analyzed
8.4EPSS 0.002
CVE-2026-49401
Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Published 2026-06-23 · Analyzed
8.4EPSS 0.002
CVE-2026-28821
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain elevated privileges.
Published 2026-03-25 · Modified
8.4EPSS 0.002
CVE-2026-28832
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to disclose kernel memory.
Published 2026-03-25 · Modified
8.4EPSS 0.002
CVE-2026-84584
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.
Published 2026-09-14 · Modified
8.4EPSS 0.002
CVE-2026-84546
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.
Published 2026-09-14 · Analyzed
8.4EPSS 0.002
CVE-2024-40771
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
Published 2025-01-15 · Modified
8.4EPSS 0.002
CVE-2026-84566
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local attacker may be able to cause unexpected system termination or corrupt kernel memory.
Published 2026-09-14 · Analyzed
8.4EPSS 0.002
CVE-2026-84580
The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.
Published 2026-09-14 · Modified
8.4EPSS 0.002
CVE-2026-40599
ClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlist
Published 2026-04-21 · Analyzed
8.4EPSS 0.001
CVE-2026-17716
Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High)
Published 2026-07-30 · Analyzed
8.4EPSS 0.001
CVE-2023-42931
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.
Published 2024-03-28 · Modified
8.3EPSS 0.012
CVE-2026-10898
Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
8.3EPSS 0.003
← Prev45 / 176Next →