VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7077CVEs
CVE-2025-54268
Bridge | Heap-based Buffer Overflow (CWE-122)
Published 2025-10-15 · Analyzed
7.8EPSS 0.003
CVE-2025-21121
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2025-02-11 · Analyzed
7.8EPSS 0.003
CVE-2025-47134
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2025-07-08 · Analyzed
7.8EPSS 0.003
CVE-2025-61804
Animate | Heap-based Buffer Overflow (CWE-122)
Published 2025-10-15 · Analyzed
7.8EPSS 0.003
CVE-2024-54509
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.
Published 2025-01-27 · Modified
7.8EPSS 0.003
CVE-2021-1868
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.
Published 2021-09-08 · Modified
7.8EPSS 0.003
CVE-2025-47103
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2025-07-08 · Analyzed
7.8EPSS 0.003
CVE-2025-49528
Illustrator | Stack-based Buffer Overflow (CWE-121)
Published 2025-07-08 · Analyzed
7.8EPSS 0.003
CVE-2025-43591
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Published 2025-07-08 · Analyzed
7.8EPSS 0.003
CVE-2025-49527
Illustrator | Stack-based Buffer Overflow (CWE-121)
Published 2025-07-08 · Analyzed
7.8EPSS 0.003
CVE-2023-32380
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. Processing a 3D model may lead to arbitrary code execution.
Published 2023-06-23 · Modified
7.8EPSS 0.003
CVE-2025-43570
Substance3D - Stager | Use After Free (CWE-416)
Published 2025-05-13 · Analyzed
7.8EPSS 0.003
CVE-2025-27175
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2025-43549
Substance3D - Stager | Use After Free (CWE-416)
Published 2025-05-13 · Analyzed
7.8EPSS 0.003
CVE-2025-27166
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2026-62909
.NET Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
7.8EPSS 0.003
CVE-2025-61816
InCopy | Heap-based Buffer Overflow (CWE-122)
Published 2025-11-11 · Analyzed
7.8EPSS 0.003
CVE-2025-43568
Substance3D - Stager | Use After Free (CWE-416)
Published 2025-05-13 · Analyzed
7.8EPSS 0.003
CVE-2025-43571
Substance3D - Stager | Use After Free (CWE-416)
Published 2025-05-13 · Analyzed
7.8EPSS 0.003
CVE-2026-20611
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
Published 2026-02-11 · Modified
7.8EPSS 0.003
CVE-2025-27178
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2025-03-11 · Analyzed
7.8EPSS 0.003
CVE-2023-40446
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing maliciously crafted input may lead to arbitrary code execution in user-installed apps.
Published 2023-12-12 · Modified
7.8EPSS 0.003
CVE-2024-41859
After Effects | Out-of-bounds Write (CWE-787)
Published 2024-09-13 · Analyzed
7.8EPSS 0.003
CVE-2022-30641
Adobe Illustrator SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2023-09-07 · Modified
7.8EPSS 0.003
CVE-2024-44126
The issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7.1, visionOS 2. Processing a maliciously crafted file may lead to heap corruption.
Published 2024-10-28 · Modified
7.8EPSS 0.003
CVE-2022-46712
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13. An app may be able to cause unexpected system termination or potentially execute code with kernel privileges.
Published 2023-02-27 · Modified
7.8EPSS 0.003
CVE-2023-27938
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in GarageBand for macOS 10.4.8. Parsing a maliciously crafted MIDI file may lead to an unexpected application termination or arbitrary code execution.
Published 2023-05-08 · Modified
7.8EPSS 0.003
CVE-2025-24170
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.
Published 2025-03-31 · Modified
7.8EPSS 0.003
CVE-2022-32813
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. An app with root privileges may be able to execute arbitrary code with kernel privileges.
Published 2022-08-24 · Modified
7.8EPSS 0.003
CVE-2026-20675
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may lead to disclosure of user information.
Published 2026-02-11 · Modified
7.8EPSS 0.003
CVE-2023-27937
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.5, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. Parsing a maliciously crafted plist may lead to an unexpected app termination or arbitrary code execution.
Published 2023-05-08 · Modified
7.8EPSS 0.003
CVE-2025-21128
Substance3D - Stager | Stack-based Buffer Overflow (CWE-121)
Published 2025-01-14 · Analyzed
7.8EPSS 0.003
CVE-2025-21129
Substance3D - Stager | Heap-based Buffer Overflow (CWE-122)
Published 2025-01-14 · Analyzed
7.8EPSS 0.003
CVE-2020-9695
Acrobat Reader | Out-of-bounds Write (CWE-787)
Published 2026-06-23 · Analyzed
7.8EPSS 0.003
CVE-2025-31184
This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.
Published 2025-03-31 · Modified
7.8EPSS 0.003
CVE-2025-54213
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2025-08-12 · Analyzed
7.8EPSS 0.003
CVE-2024-27826
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma 14.5, macOS Ventura 13.6.8, tvOS 17.5, visionOS 1.3, watchOS 10.5. A local attacker may be able to cause unexpected system shutdown.
Published 2024-07-29 · Modified
7.8EPSS 0.003
CVE-2025-54210
InDesign Desktop | Out-of-bounds Write (CWE-787)
Published 2025-08-12 · Analyzed
7.8EPSS 0.003
CVE-2022-32948
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
Published 2022-12-15 · Modified
7.8EPSS 0.003
CVE-2024-23234
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to execute arbitrary code with kernel privileges.
Published 2024-03-08 · Modified
7.8EPSS 0.003
← Prev78 / 177Next →