CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 27, 2025

Apple Products AirPlay Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the AirPlay feature of various Apple products, including iPadOS, macOS Ventura, macOS Sonoma, visionOS, and tvOS. This vulnerability allows an attacker on the local network to cause an unexpected app termination by exploiting a type confusion issue. The problem has been addressed with improved input validation and memory handling.

4.7
Jan 27, 2025

Apple AirPlay Input Validation Vulnerability Leading to Memory Corruption and System Termination

A vulnerability in the AirPlay feature across multiple Apple platforms, including visionOS, iOS, iPadOS, macOS Sequoia, watchOS, and tvOS, allows an attacker on the local network to exploit input validation issues. This exploitation could lead to unexpected termination of applications, corruption of process memory, or even cause the system to terminate unexpectedly. The vulnerability arises from improper handling of input, which could be manipulated to disrupt normal application or system processes.

4.8
Jan 27, 2025

Apple CoreMedia and CoreAudio Vulnerability Leading to Unexpected App Termination

A vulnerability exists in the CoreMedia and CoreAudio frameworks of multiple Apple operating systems, including iPadOS, macOS Ventura, macOS Sonoma, watchOS, and tvOS. This vulnerability allows for parsing certain files in a way that can cause an application to terminate unexpectedly. The issue has been attributed to a type confusion problem, which has been addressed with improved validation checks.

4.7
Jan 27, 2025

Apple CoreMedia and CoreAudio Vulnerability Leading to Unexpected App Termination

A vulnerability exists in the CoreMedia and CoreAudio frameworks of multiple Apple operating systems, including iPadOS, macOS Ventura, macOS Sonoma, watchOS, and tvOS. This vulnerability allows for parsing certain files in a way that causes an unexpected termination of the application. The issue has been attributed to a type confusion problem, which has been addressed with improved validation checks.

4.7
Jan 27, 2025

Apple macOS Downgrade Vulnerability in Intel-Based Macs Allowing Unauthorized File System Modifications

A vulnerability exists in macOS Ventura, Sequoia, and Sonoma on Intel-based Mac computers, allowing apps to modify protected parts of the file system. This issue was addressed with additional code-signing restrictions.

4.3
Jan 27, 2025

Apple macOS Ventura, Sequoia, and Sonoma Logic Issue in AppleMobileFileIntegrity Allowing Unauthorized File System Modifications

A logic vulnerability has been identified in the AppleMobileFileIntegrity component of macOS Ventura 13.7.3, macOS Sequoia 15.3, and macOS Sonoma 14.7.3. This vulnerability allows applications to modify protected areas of the file system, potentially leading to unauthorized changes or access.

4.7
Jan 27, 2025

Apple macOS Object Lifetime Management Vulnerability Leading to Application Termination

A vulnerability exists in Apple macOS Ventura, Sequoia, and Sonoma, all through version 15.3, as well as in macOS Ventura 13.7.3. This vulnerability arises from improper management of object lifetimes, which could allow an attacker to cause unexpected application termination.

4.7
Jan 27, 2025

Apple Kernel Memory Corruption Vulnerability Allowing Arbitrary Code Execution

A vulnerability in the kernel of Apple iPadOS and macOS versions prior to the latest release allows apps to cause unexpected system termination or write to kernel memory. This issue arises from improper memory handling, which could be exploited to execute arbitrary code with kernel privileges.

4.3
Jan 27, 2025

Apple LaunchServices User Fingerprinting Vulnerability

A vulnerability in the LaunchServices component of multiple Apple operating systems allows apps to fingerprint users. This issue arises from inadequate redaction of sensitive information, potentially enabling the tracking of user behavior or preferences.

4.6
Jan 27, 2025

Apple LaunchServices Privacy Bypass Vulnerability in Multiple macOS Versions

A vulnerability allowing applications to bypass Privacy preferences has been identified in the LaunchServices component of macOS Ventura 13.7.3, macOS Sequoia 15.3, and macOS Sonoma 14.7.3. This issue arises from an access problem that has been addressed with additional sandbox restrictions.

4.8
Jan 27, 2025

Apple LaunchServices Path Handling Vulnerability Allowing Sandbox Bypass

A path handling vulnerability in the LaunchServices component of macOS Ventura, Sequoia, and Sonoma was addressed with improved validation. This issue allowed applications to read files outside of their designated sandbox, potentially leading to unauthorized access to user data.

4.4
Jan 27, 2025

Apple macOS Ventura, Sequoia, and Sonoma Mobile File Integrity Permissions Vulnerability

A permissions vulnerability has been identified in the Apple Mobile File Integrity component of macOS Ventura 13.7.3, macOS Sequoia 15.3, and macOS Sonoma 14.7.3. This vulnerability allows applications to modify protected areas of the file system. The issue stems from inadequate permissions checks, which have been addressed in the latest updates.

4.4
Jan 27, 2025

Apple Safari, macOS, iOS, iPadOS, and visionOS User Interface Spoofing Vulnerability

A user interface spoofing vulnerability has been identified in Apple Safari 18.3, macOS Sequoia 15.3, iOS 18.3, iPadOS 18.3, and visionOS 2.3. This vulnerability allows a malicious website to manipulate the user interface, potentially leading to deceptive user experiences.

4.9
Jan 27, 2025

Apple macOS AirPlay Memory Corruption Vulnerability Leading to Denial-of-Service

A memory corruption vulnerability has been identified in the AirPlay feature of Apple macOS Sequoia 15.3 and macOS Sonoma 14.7.3. This vulnerability allows an attacker on the local network to cause an unexpected application termination. The issue arises from a type confusion problem that has been addressed with improved validation checks.

4.7
Jan 27, 2025

Apple macOS Downgrade Vulnerability in AppleMobileFileIntegrity Allowing Access to Sensitive User Data

A vulnerability exists in the AppleMobileFileIntegrity component of macOS Ventura, Sequoia, and Sonoma, allowing apps to access sensitive user data. This issue arises from a downgrade vulnerability that was addressed with additional code-signing restrictions. The vulnerability affects several different versions and/or ranges of macOS Ventura, Sequoia, and Sonoma.

4.7
Jan 27, 2025

Apple macOS Sequoia Access Vulnerability in SharedFileList Component

A vulnerability in the SharedFileList component of Apple macOS Sequoia was addressed in version 15.3. This access issue allowed applications to potentially access protected user data. The vulnerability stemmed from insufficient sandbox restrictions, which could be exploited to reach sensitive information.

4.7
Jan 27, 2025

Apple Products Privilege Escalation Vulnerability in the Kernel

A vulnerability allowing a malicious application to gain root privileges has been identified in the kernel of multiple Apple operating systems, including macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3, iOS 18.3, and iPadOS 18.3. This issue arises from a permissions problem that has been addressed with additional restrictions.

4.5
Jan 27, 2025

Apple Audio Component Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the Apple Audio component of macOS Ventura 13.7.3, macOS Sequoia 15.3, and macOS Sonoma 14.7.3. This vulnerability arises from improper memory handling, which can lead to an unexpected application termination when a file is parsed.

4.7
Jan 27, 2025

Apple iOS and iPadOS Managed Configuration Symlink Handling Vulnerability Leading to Unauthorized Modification of System Files

A vulnerability exists in the Managed Configuration feature of iOS and iPadOS, specifically in versions prior to iPadOS 17.7.4 and iOS 18.3. This vulnerability allows for the unauthorized modification of protected system files by restoring a maliciously crafted backup file. The issue arises from improper handling of symbolic links, which can be exploited to manipulate file system permissions and access sensitive system areas.

4.8
Jan 27, 2025

Apple macOS Symlink Validation Vulnerability Allowing Access to Protected User Data

A vulnerability exists in the validation of symlinks within various components of macOS, including Ventura, Sequoia, and Sonoma. This flaw may allow an application to access protected user data or create symlinks to restricted areas of the disk, potentially leading to unauthorized data exposure or modification.

4.4
Jan 27, 2025

Apple CoreRoutine Vulnerability Allowing Location Access in Multiple macOS and iPadOS Versions

A vulnerability in the CoreRoutine component of Apple operating systems can allow an application to access a user's current location. This issue affects iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, and macOS Ventura 13.7.3. The vulnerability arises from insufficient checks, which could be exploited by apps to determine location information.

4.7
Jan 27, 2025

Apple macOS Sequoia Sensitive Data Access Vulnerability

A vulnerability exists in macOS Sequoia that allows applications to access user-sensitive data. This issue has been addressed in the macOS Sequoia 15.3 update.

4.4
Jan 27, 2025

Apple macOS Ventura, Sequoia, and Sonoma Logic Issue in AppleMobileFileIntegrity Allowing Access to Contacts

A logic issue in the AppleMobileFileIntegrity component of macOS Ventura 13.7.3, macOS Sequoia 15.3, and macOS Sonoma 14.7.3, allows applications to access information about a user's contacts. This vulnerability was addressed with improved restrictions.

4.4
Jan 27, 2025

Apple macOS Sequoia Arbitrary File Access Vulnerability

A vulnerability in macOS Sequoia that allows a malicious application to access arbitrary files has been identified. This issue arises from inadequate state management and affects macOS Sequoia versions prior to 15.3.

4.3
Jan 27, 2025

Apple LaunchServices Race Condition Vulnerability Allowing Access to User-Sensitive Data

A race condition vulnerability in the LaunchServices component of macOS Ventura, Sequoia, and Sonoma was addressed with additional validation. This issue allowed apps to potentially access user-sensitive data.

4.2
Jan 27, 2025

Apple macOS Ventura and Sonoma Removable Volume Access Vulnerability

A permissions vulnerability exists in macOS Ventura 13.7.3 and macOS Sonoma 14.7.3, allowing applications to access removable volumes without user consent. This issue was addressed by implementing additional restrictions.

4.3
Jan 27, 2025

Apple TV App Sensitive Location Information Access Vulnerability

A vulnerability exists in the Apple TV app on macOS Sequoia and macOS Sonoma, allowing unauthorized access to sensitive location information. This issue arises from inadequate data protection measures, which could enable an application to read private location details without proper authorization.

4.3
Jan 27, 2025

Apple macOS Sequoia Protected User Data Access Vulnerability

A vulnerability exists in macOS Sequoia that allows applications to access protected user data. This issue has been addressed in the macOS Sequoia 15.3 update.

4.4
Jan 27, 2025

Apple ImageIO Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the ImageIO component of multiple Apple operating systems, including iPadOS, macOS Ventura, macOS Sonoma, watchOS, and tvOS. This vulnerability arises from improper memory handling when processing images, which can lead to unexpected application termination or system resource exhaustion.

4.7
Jan 27, 2025

Apple CoreMedia Privilege Escalation Vulnerability

A use-after-free vulnerability in the CoreMedia component of multiple Apple operating systems, including iOS, iPadOS, macOS Sequoia, watchOS, tvOS, and visionOS, was addressed with improved memory management. This vulnerability allowed a malicious application to elevate privileges and may have been actively exploited in versions of iOS prior to 17.2.

6.6
Jan 27, 2025

Apple macOS SharedFileList Component Logic Vulnerability Allowing Unauthorized File System Access

A logic vulnerability in the SharedFileList component of Apple macOS has been identified, allowing an attacker to gain access to protected areas of the file system. This issue affects multiple macOS versions, including Sonoma 14.7.2, Sequoia 15.2, and Ventura 13.7.2. The vulnerability arises from inadequate restrictions in file handling, which could be exploited to access sensitive data or files without proper authorization.

4.4
Jan 27, 2025

Apple Products Autocomplete Contact Information Logging Vulnerability

A vulnerability exists in various Apple products, including macOS Sequoia 15.2, iOS 18.2, and iPadOS 18.2. This issue allows an application to access autocompleted contact details from Messages and Mail, which may be recorded in the system logs. The vulnerability arises from inadequate redaction of sensitive information before it is logged.

4.4
Jan 27, 2025

Apple macOS Sequoia Sensitive Data Access Vulnerability

A vulnerability exists in macOS Sequoia that allows apps to access user-sensitive data. This issue has been addressed with improved redaction of sensitive information and is fixed in macOS Sequoia 15.2.

4.7
Jan 27, 2025

Apple macOS Protected User Data Access Vulnerability

A vulnerability exists in multiple macOS versions, including Sonoma 14.7.2, Sequoia 15.2, and Ventura 13.7.2, allowing apps to access protected user data. This issue stems from a logic flaw that was addressed with improved file handling and state management.

4.7
Jan 27, 2025

Apple WebKit Memory Corruption Vulnerability

A vulnerability in the WebKit component of multiple Apple operating systems, including visionOS, tvOS, watchOS, iOS, iPadOS, and macOS Sequoia, has been identified. This vulnerability allows processing of maliciously crafted web content, leading to memory corruption. The issue arises from improper handling of memory, which could potentially be exploited to execute arbitrary code or cause other unintended behaviors.

5.0
Jan 27, 2025

Apple Safari Private Browsing Authentication Bypass Vulnerability

A vulnerability exists in Apple Safari's private browsing feature, allowing tabs to be accessed without authentication. This issue affects Safari 18.2 on macOS Sequoia 15.2, watchOS 11.2, iOS 18.2, and iPadOS 18.2. The vulnerability arises from a logic flaw in state management, which could potentially be exploited to access private browsing data without proper authorization.

4.7
Jan 27, 2025

Apple APFS User-Sensitive Data Access Vulnerability

A vulnerability exists in the Apple APFS component of multiple operating systems, including macOS Ventura, macOS Sonoma, visionOS, tvOS, and watchOS. This vulnerability allows apps to access user-sensitive data without proper authorization. The issue has been addressed in the latest versions of these operating systems.

4.8
Jan 27, 2025

Apple macOS WindowServer Lock Screen Keyboard Event Capture Vulnerability

A vulnerability in the WindowServer component of Apple macOS Sonoma, Sequoia, and Ventura allows apps to capture keyboard events from the lock screen. This issue arises from a logic flaw in state management, which could potentially be exploited to intercept keystrokes while the device is locked.

4.7
Jan 27, 2025

Apple QuickTime Player Sandbox Bypass Vulnerability Allowing Unauthorized File Access

A vulnerability exists in QuickTime Player on macOS Sonoma 14.7.2, macOS Sequoia 15.2, and macOS Ventura 13.7.2, allowing applications to read and write files outside of their designated sandbox. This issue arises from insufficient entitlement checks, which could enable unauthorized access to user data.

4.8
Jan 27, 2025

Apple macOS Sequoia NVRAM Variable Modification Vulnerability

A vulnerability exists in Apple macOS Sequoia that allows an application to edit NVRAM variables. This issue arises from insufficient validation of environment variables, potentially leading to unauthorized modifications. The vulnerability affects all versions of macOS Sequoia prior to 15.2.

4.4
Jan 27, 2025

Apple Products Password Autofill Authentication Bypass Vulnerability

A vulnerability exists in multiple Apple products, including macOS Sequoia 15.2, watchOS 11.2, visionOS 2.2, iOS 18.2, and iPadOS 18.2. This vulnerability allows the password autofill feature to incorrectly fill in passwords after a failed authentication attempt. The issue arises from a logic flaw in how password autofill handles authentication states, potentially leading to unauthorized access to sensitive accounts or information.

4.7
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component, available on iPhone XS and later, as well as various iPad and Apple Watch models. This vulnerability allows an app to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue has been addressed with improved bounds checks.

4.4
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component, available on various Apple devices including iPhone, iPad, and Apple Watch. This vulnerability allows an application to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue arises from inadequate bounds checks, which could be exploited by malicious applications to manipulate memory in a way that disrupts normal operations.

4.7
Jan 27, 2025

Apple macOS SharedFileList Overwrite Vulnerability

A path handling vulnerability has been identified in the SharedFileList component of Apple macOS Ventura 13.7.2, macOS Sonoma 14.7.2, and macOS Sequoia 15.2. This vulnerability allows applications to overwrite arbitrary files, potentially leading to unauthorized modifications of user data or system files.

4.4
Jan 27, 2025

Apple macOS Sonoma and Sequoia Logging Vulnerability Allowing Location Data Access

A vulnerability exists in the logging mechanism of macOS Sonoma 14.7.2 and macOS Sequoia 15.2, which may allow applications to access sensitive location information. This issue was addressed by improving how logs are sanitized.

4.7
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component of Apple operating systems, including macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2, and iPadOS 18.2. This vulnerability allows an application to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue arises from inadequate bounds checks, which could be exploited by malicious applications to manipulate memory in a way that disrupts normal operations.

4.7
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component, available on various Apple devices including iPhone, iPad, and Apple Watch. This vulnerability allows an app to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue has been addressed with improved bounds checks.

4.7
Jan 27, 2025

Apple macOS SharedFileList Launch Daemon Approval Vulnerability

A permissions vulnerability exists in the SharedFileList component of Apple macOS Sonoma and Sequoia. This issue allows an application to approve a launch daemon without user consent. The vulnerability has been addressed with additional restrictions in macOS Sonoma 14.7.2 and macOS Sequoia 15.2.

4.4
Jan 27, 2025

Apple Face Gallery Apple Account Fingerprinting Vulnerability

A vulnerability exists in the Face Gallery component of Apple Watch, iOS, and iPadOS, specifically in versions prior to watchOS 11.2, iOS 18.2, and iPadOS 18.2. This vulnerability allows a system binary to fingerprint a user's Apple Account, potentially enabling tracking of the user's activity. The issue was caused by improper handling of certain flags, which has been addressed in the latest software updates.

3.9
Jan 27, 2025

Apple macOS ASP TCP Out-of-Bounds Write Vulnerability Allowing Kernel Memory Corruption

A vulnerability in the ASP TCP component of Apple macOS can lead to unexpected system termination or corruption of kernel memory. This out-of-bounds write issue was addressed with improved input validation. The vulnerability is present in several versions of macOS Sonoma and Sequoia.

4.8