VendorsApplemacosany version
Vulnerabilities

Apple MACOS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7031CVEs
CVE-2026-27283
InDesign Desktop | Use After Free (CWE-416)
Published 2026-04-14 · Analyzed
7.8EPSS 0.004
CVE-2026-34638
Premiere Pro | Use After Free (CWE-416)
Published 2026-05-12 · Analyzed
7.8EPSS 0.004
CVE-2026-47955
Acrobat Reader | Use After Free (CWE-416)
Published 2026-06-09 · Analyzed
7.8EPSS 0.004
CVE-2022-34260
Adobe Illustrator Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-08-11 · Modified
7.8EPSS 0.004
CVE-2023-42841
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1. An app may be able to execute arbitrary code with kernel privileges.
Published 2023-10-25 · Modified
7.8EPSS 0.004
CVE-2025-21163
Illustrator | Stack-based Buffer Overflow (CWE-121)
Published 2025-02-11 · Analyzed
7.8EPSS 0.004
CVE-2024-20792
Adobe Illustrator TIF File Parsing Use-After-Free Remote memory corruption
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2023-24068
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's ability to insert malicious code into pre-existing attachments or replace them completely. A threat actor can forward the existing attachment in the corresponding conversation to external groups, and the name and size of the file will not change, allowing the malware to masquerade as another file. NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.
Published 2023-01-23 · Modified
7.8EPSS 0.004
CVE-2023-38212
ZDI-CAN-21093: Adobe Dimension GLB File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2023-08-09 · Modified
7.8EPSS 0.004
CVE-2022-35701
Adobe Bridge SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-09-19 · Modified
7.8EPSS 0.004
CVE-2024-39377
Media Encoder | Out-of-bounds Write (CWE-787)
Published 2024-09-13 · Analyzed
7.8EPSS 0.004
CVE-2024-54489
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Running a mount command may unexpectedly execute arbitrary code.
Published 2024-12-11 · Modified
7.8EPSS 0.004
CVE-2024-47411
Animate | Access of Uninitialized Pointer (CWE-824)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2024-47416
Animate | Integer Overflow or Wraparound (CWE-190)
Published 2024-10-09 · Analyzed
7.8EPSS 0.004
CVE-2022-32908
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. A user may be able to elevate privileges.
Published 2022-09-20 · Modified
7.8EPSS 0.004
CVE-2024-34121
Illustrator | Integer Overflow or Wraparound (CWE-190)
Published 2024-09-13 · Analyzed
7.8EPSS 0.004
CVE-2025-21160
Illustrator | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2025-02-11 · Analyzed
7.8EPSS 0.004
CVE-2021-1751
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.
Published 2021-04-02 · Modified
7.8EPSS 0.004
CVE-2024-41857
Illustrator | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2024-09-13 · Analyzed
7.8EPSS 0.004
CVE-2025-43575
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2025-06-10 · Analyzed
7.8EPSS 0.004
CVE-2024-30275
Adobe Aero Beta has an arbitrary code execution vulnerability when parsing svg files
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2023-41071
A use-after-free issue was addressed with improved memory management. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Ventura 13.6. An app may be able to execute arbitrary code with kernel privileges.
Published 2023-09-26 · Modified
7.8EPSS 0.004
CVE-2021-30704
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.
Published 2021-09-08 · Modified
7.8EPSS 0.004
CVE-2021-30781
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A local attacker may be able to cause unexpected application termination or arbitrary code execution.
Published 2021-09-08 · Modified
7.8EPSS 0.004
CVE-2023-22235
Adobe InCopy SVG file Use After Free Arbitrary code execution
Published 2023-04-12 · Modified
7.8EPSS 0.004
CVE-2023-22246
Adobe Animate FLA files Use After Free Arbitrary code execution
Published 2023-02-17 · Modified
7.8EPSS 0.004
CVE-2024-23212
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.
Published 2024-01-23 · Modified
7.8EPSS 0.004
CVE-2024-39389
Adobe Indesign PDF File Parsing Stack Based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2021-43757
Adobe Media Encoder 3GP File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-07-12 · Modified
7.8EPSS 0.004
CVE-2022-26762
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious application may be able to execute arbitrary code with system privileges.
Published 2022-11-01 · Modified
7.8EPSS 0.004
CVE-2024-30295
When Animate parses FLA files, there is a UAF vulnerability caused by referencing uninitialized memory at Animate.exe+0x1149dcf
Published 2024-05-16 · Analyzed
7.8EPSS 0.004
CVE-2023-47043
ZDI-CAN-21699: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2022-44514
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2022-44518
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2022-44520
Acrobat Reader | Use After Free (CWE-416)
Published 2024-12-18 · Analyzed
7.8EPSS 0.004
CVE-2023-47040
ZDI-CAN-21698: Adobe Media Encoder MP4 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2023-11-16 · Modified
7.8EPSS 0.004
CVE-2024-41840
ZDI-CAN-24607: Adobe Bridge JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2024-08-14 · Analyzed
7.8EPSS 0.004
CVE-2024-49553
Media Encoder | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-49551
Media Encoder | Out-of-bounds Write (CWE-787)
Published 2024-12-10 · Analyzed
7.8EPSS 0.004
CVE-2024-34099
ZDI-CAN-XXXX: [Pwn2Own] Acrobat sandbox bypass part 2 of 2
Published 2024-05-15 · Analyzed
7.8EPSS 0.004
← Prev68 / 176Next →