Known vulnerabilities in macOS 14.8.5 23J423

Vendor: Apple Inc.
Software: macOS
Version: 14.8.5 23J423
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 169
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting macOS version 14.8.5 23J423 macOS 14.8.5 23J423 is affected by 169 vulnerabilities: 3 high, 24 medium, 142 low Critical High Medium Low

Vulnerabilities (169)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU143798 - Improper Access Control
CVE-2026-28900
CWE-284 Medium
No
No
15.7.8 24G824, 14.8.8 23J620 17.08.2026 SB2026081773
SB2026081774
#VU143797 - Improper Access Control
CVE-2026-20672
CWE-284 Low
No
No
15.7.8 24G824, 14.8.8 23J620 17.08.2026 SB2026081773
SB2026081774
#VU143753 - Improper input validation
CVE-2026-64774
CWE-20 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 4 more
#VU143747 - Memory corruption
CVE-2026-28911
CWE-119 Low
No
No
26.6 25G72, 14.8.8 23J620 17.08.2026 SB2026081772
SB2026081774
#VU143746 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-43723
CWE-22 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 5 more
#VU143745 - Memory corruption
CVE-2026-64724
CWE-119 Medium
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 5 more
#VU143743 - Permissions, Privileges, and Access Controls
CVE-2026-64738
CWE-264 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 1 more
#VU143740 - Out-of-bounds write
CVE-2026-64739
CWE-787 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 5 more
#VU143741 - State Issues
CVE-2026-43766
CWE-371 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
#VU143738 - Improper input validation
CVE-2026-4424
CWE-20 Medium
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 4 more
#VU143739 - Improper input validation
CVE-2026-28973
CWE-20 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 3 more
#VU143737 - State Issues
CVE-2026-64721
CWE-371 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 5 more
#VU143735 - Exposure of sensitive information to an unauthorized actor
CVE-2026-43754
CWE-200 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 1 more
#VU143733 - Improper Access Control
CVE-2026-64723
CWE-284 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 1 more
#VU143717 - Memory corruption
CVE-2026-64709
CWE-119 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 5 more
#VU143715 - Use After Free
CVE-2026-43778
CWE-416 Low
No
No
26.6 25G72, 14.8.8 23J620, 15.7.8 24G824 17.08.2026 SB2026081772
SB2026081773
SB2026081774
and 5 more
#VU137084 - Improper input validation
CVE-2026-43706
CWE-20 Medium
No
No
26.5.2 25F84, 14.8.8 23J620, 15.7.8 24G824 08.07.2026 SB2026070836
SB2026081773
SB2026081774
and 4 more
#VU137085 - Memory corruption
CVE-2026-43703
CWE-119 Medium
No
No
26.5.2 25F84, 14.8.8 23J620, 15.7.8 24G824 08.07.2026 SB2026070836
SB2026081773
SB2026081774
and 4 more
#VU137083 - Improper input validation
CVE-2026-39868
CWE-20 Low
No
No
26.5.2 25F84, 14.8.8 23J620, 15.7.8 24G824 08.07.2026 SB2026070836
SB2026081773
SB2026081774
and 5 more
#VU131044 - Improper Access Control
CVE-2026-28983
CWE-284 Low
No
No
26.5 25F71, 14.8.8 23J620, 15.7.8 24G824 12.05.2026 SB2026051205
SB2026051214
SB2026051215
and 5 more


Showing elements 1 - 20 out of 169