macOS
6,100 CVEs tracked. 83 of them are in CISA KEV.
This hub aggregates every CVE we track for macOS, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
macOS CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 67 |
| 2024-11 | 7 |
| 2024-12 | 59 |
| 2025-01 | 93 |
| 2025-02 | 2 |
| 2025-03 | 149 |
| 2025-04 | 22 |
| 2025-05 | 67 |
| 2025-06 | 1 |
| 2025-07 | 79 |
| 2025-08 | 8 |
| 2025-09 | 75 |
| 2025-10 | 4 |
| 2025-11 | 94 |
| 2025-12 | 65 |
| 2026-01 | 8 |
| 2026-02 | 64 |
| 2026-03 | 79 |
| 2026-04 | 15 |
| 2026-05 | 91 |
| 2026-06 | 51 |
| 2026-07 | 160 |
| 2026-08 | 35 |
| 2026-09 | 222 |
Severity
How the 6,100 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical573
- High2,440
- Medium2,748
- Low339
Latest CVEs
The 15 most recently published vulnerabilities affecting macOS.
- CVE-2026-65409A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7...5.5
- CVE-2026-84559A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restrict...5.5
- CVE-2026-43741A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.5.5
- CVE-2026-28937This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.5.5
- CVE-2026-86876An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Taho...5.2
- CVE-2026-84518This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a us...4.3
- CVE-2026-84631This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.7.8
- CVE-2026-84563A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.7.5
- CVE-2026-84534A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visi...5.5
- CVE-2026-43690A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.4.7
- CVE-2026-84522A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.5.9
- CVE-2026-86909A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.4.4
- CVE-2026-43686A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26...8.8
- CVE-2026-84575An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS ...7.8
- CVE-2026-64756A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access u...5.5
Product grouping is registry-driven, with AI assist and human review. How it works