Known vulnerabilities in macOS 26.0.1 25A8364 - page 23

Vendor: Apple Inc.
Software: macOS
Version: 26.0.1 25A8364
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 608
Public exploits: 10
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting macOS version 26.0.1 25A8364 macOS 26.0.1 25A8364 is affected by 608 vulnerabilities: 2 critical, 19 high, 94 medium, 493 low Critical High Medium Low

Vulnerabilities (608)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119942 - Permissions, Privileges, and Access Controls
CVE-2025-43526
CWE-264 Medium
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
#VU119941 - Missing Authorization
CVE-2025-43428
CWE-862 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
SB2025121305
SB2025121309
#VU119940 - Memory corruption
CVE-2025-43533
CWE-119 Low
No
No
26.2 25C56, 14.8.4 23J319, 15.7.4 24G517 13.12.2025 SB2025121304
SB2025121305
SB2025121306
and 5 more
#VU119933 - Improper Access Control
CVE-2025-43530
CWE-284 Low
No
No
26.2 25C56, 14.8.3 23J220, 15.7.3 24G419 13.12.2025 SB2025121304
SB2025121308
SB2025121310
and 1 more
#VU119932 - Improper Access Control
CVE-2025-43416
CWE-284 Low
No
No
26.2 25C56, 14.8.3 23J220, 15.7.3 24G419 13.12.2025 SB2025121304
SB2025121308
SB2025121311
#VU119931 - Permissions, Privileges, and Access Controls
CVE-2025-43527
CWE-264 Low
No
No
26.2 25C56, 15.7.3 24G419 13.12.2025 SB2025121304
SB2025121311
#VU119930 - Improper input validation
CVE-2025-43514
CWE-20 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
#VU119929 - Information Exposure Through Log Files
CVE-2025-43538
CWE-532 Low
No
No
26.2 25C56, 14.8.3 23J220 13.12.2025 SB2025121304
SB2025121305
SB2025121307
and 3 more
#VU119928 - Information Exposure Through Log Files
CVE-2025-46277
CWE-532 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
SB2025121307
SB2025121309
#VU119926 - Exposure of sensitive information to an unauthorized actor
CVE-2025-43509
CWE-200 Low
No
No
26.2 25C56, 14.8.3 23J220, 15.7.3 24G419 13.12.2025 SB2025121304
SB2025121308
SB2025121311
#VU119909 - Use After Free
CVE-2025-43511
CWE-416 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 24 more
#VU119908 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-43531
CWE-362 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 24 more
#VU119907 - Memory corruption
CVE-2025-43501
CWE-119 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 22 more
#VU119906 - Memory corruption
CVE-2025-43535
CWE-119 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 22 more
#VU119905 - Use After Free
CVE-2025-43536
CWE-416 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121309
and 21 more
#VU119904 - Type confusion
CVE-2025-43541
CWE-843 Low
Public exploit available
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 22 more
#VU119903 - Permissions, Privileges, and Access Controls
CVE-2025-46282
CWE-264 Low
No
No
26.2 25C56 13.12.2025 SB2025121302
SB2025121303
SB2025121304
#VU119902 - Use After Free
CVE-2025-43529
CWE-416 Critical
Public exploit available
Exploited
26.2 25C56, 26.3 25D125 13.12.2025 SB2025121301
SB2025121303
SB2025121304
and 29 more
#VU119833 - Out-of-bounds write
CVE-2025-14174
CWE-787 Critical
Public exploit available
Exploited
26.2 25C56, 26.3 25D125 11.12.2025 SB2025121118
SB2025121301
SB2025121303
and 21 more
#VU97450 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2024-8906
CWE-451 Medium
No
No
26.2 25C56 17.09.2024 SB2024091804
SB20240918137
SB20240918138
and 9 more


Showing elements 441 - 460 out of 608