Known vulnerabilities in macOS 26.0.1 25A362 - page 17

Vendor: Apple Inc.
Software: macOS
Version: 26.0.1 25A362
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 424
Public exploits: 6
Known exploited (KEV): 5
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting macOS version 26.0.1 25A362 macOS 26.0.1 25A362 is affected by 424 vulnerabilities: 2 critical, 12 high, 68 medium, 342 low Critical High Medium Low

Vulnerabilities (424)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118056 - Permissions, Privileges, and Access Controls
CVE-2025-43414
CWE-264 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
#VU118055 - Improper Access Control
CVE-2025-43408
CWE-284 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
#VU118054 - Exposure of sensitive information to an unauthorized actor
CVE-2025-43335
CWE-200 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
#VU118047 - Security Features
CVE-2025-43502
CWE-254 Low
No
No
26.1 25B78 04.11.2025 SB2025110420
SB2025110422
SB2025110435
and 1 more
#VU118045 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-43503
CWE-451 Medium
No
No
26.1 25B78 04.11.2025 SB2025110420
SB2025110422
SB2025110435
and 3 more
#VU118044 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-43493
CWE-451 Medium
No
No
26.1 25B78 04.11.2025 SB2025110420
SB2025110422
SB2025110435
and 2 more
#VU118036 - Improper Access Control
CVE-2025-43334
CWE-284 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
#VU118035 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-43463
CWE-22 Low
No
No
26.1 25B78, 14.8.3 23J220, 15.7.3 24G419 04.11.2025 SB2025110422
SB2025121308
SB2025121311
#VU118028 - Out-of-bounds write
CVE-2025-43380
CWE-787 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
#VU118027 - Improper Access Control
CVE-2025-43499
CWE-284 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
and 1 more
#VU118026 - State Issues
CVE-2025-43473
CWE-371 Low
No
No
26.1 25B78 04.11.2025 SB2025110422
#VU118024 - Permissions, Privileges, and Access Controls
CVE-2025-43476
CWE-264 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
#VU118023 - Improper input validation
CVE-2025-43500
CWE-20 Low
No
No
26.1 25B78 04.11.2025 SB2025110422
SB2025110435
SB2025110436
and 1 more
#VU118022 - Improper Access Control
CVE-2025-43404
CWE-284 Low
No
No
26.1 25B78 04.11.2025 SB2025110422
#VU118021 - Improper Access Control
CVE-2025-43406
CWE-284 Low
No
No
26.1 25B78 04.11.2025 SB2025110422
#VU118019 - Improper input validation
CVE-2025-43391
CWE-20 Low
No
No
26.1 25B78, 14.8.2 23J126, 15.7.2 24G325 04.11.2025 SB2025110422
SB2025110423
SB2025110424
and 1 more
#VU114416 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-6442
CWE-444 Medium
No
No
14.8.2 23J126, 15.7.2 24G325, 26.1 25B78 25.08.2025 SB2024100844
SB2025082565
SB2025082567
and 10 more
#VU112067 - Protection Mechanism Failure
CVE-2025-32462
CWE-693 Low
Public exploit available
No
26.1 25B78 01.07.2025 SB2025070109
SB2025070111
SB2025070112
and 42 more
#VU99358 - Inefficient Regular Expression Complexity
CVE-2024-49761
CWE-1333 Medium
No
No
14.8.2 23J126, 15.7.2 24G325, 26.1 25B78 28.10.2024 SB2024102837
SB2024110504
SB20241108111
and 38 more
#VU96970 - Resource exhaustion
CVE-2024-43398
CWE-400 Medium
No
No
14.8.2 23J126, 15.7.2 24G325, 26.1 25B78 10.09.2024 SB2024091006
SB2024091007
SB2024091008
and 28 more


Showing elements 321 - 340 out of 424