Skip to content
Appaloosa Scout

macOS

macOS 13.7.6

Official advisory

30 CVEs fixed by this release.

Release date
2025-05-12
End of support
2025-09-15 EOL
CVEs fixed
30
CISA KEV
0
Critical
0
High
1
NVD pending
29

CVEs fixed

CVE Severity
CVE-2024-8176

[Apple libexpat] Multiple issues in libexpat, including unexpected app termination or arbitrary code execution

HIGH 7.5
CVE-2025-24142

[Apple Notification Center] An app may be able to access sensitive user data

N/A
CVE-2025-24144

[Apple Kernel] An app may be able to leak sensitive kernel state

N/A
CVE-2025-24155

[Apple WebContentFilter] An app may be able to disclose kernel memory

N/A
CVE-2025-24258

[Apple DiskArbitration] An app may be able to gain root privileges

N/A
CVE-2025-24274

[Apple Mobile Device Service] A malicious app may be able to gain root privileges

N/A
CVE-2025-30440

[Apple Libinfo] An app may be able to bypass ASLR

N/A
CVE-2025-30442

[Apple Software Update] An app may be able to gain elevated privileges

N/A
CVE-2025-30448

[Apple iCloud Document Sharing] An attacker may be able to turn on sharing of an iCloud folder without authentication

N/A
CVE-2025-30453

[Apple DiskArbitration] A malicious app may be able to gain root privileges

N/A
CVE-2025-31196

[Apple CoreGraphics] Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memo…

N/A
CVE-2025-31208

[Apple CoreAudio] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-31209

[Apple CoreGraphics] Parsing a file may lead to disclosure of user information

N/A
CVE-2025-31213

[Apple Security] An app may be able to access associated usernames and websites in a user's iCloud Keychain

N/A
CVE-2025-31219

[Apple Kernel] An attacker may be able to cause unexpected system termination or corrupt kernel memory

N/A
CVE-2025-31220

[Apple Weather] A malicious app may be able to read sensitive location information

N/A
CVE-2025-31221

[Apple Security] A remote attacker may be able to leak memory

N/A
CVE-2025-31222

[Apple mDNSResponder] A user may be able to elevate privileges

N/A
CVE-2025-31224

[Apple Sandbox] An app may be able to bypass certain Privacy preferences

N/A
CVE-2025-31232

[Apple Installer] A sandboxed app may be able to access sensitive user data

N/A
CVE-2025-31233

[Apple CoreMedia] Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process…

N/A
CVE-2025-31235

[Apple Audio] An app may be able to cause unexpected system termination

N/A
CVE-2025-31237

[Apple afpfs] Mounting a maliciously crafted AFP network share may lead to system termination

N/A
CVE-2025-31239

[Apple CoreMedia] Parsing a file may lead to an unexpected app termination

N/A
CVE-2025-31240

[Apple afpfs] Mounting a maliciously crafted AFP network share may lead to system termination

N/A
CVE-2025-31241

[Apple Kernel] A remote attacker may cause an unexpected app termination

N/A
CVE-2025-31242

[Apple StoreKit] An app may be able to access sensitive user data

N/A
CVE-2025-31245

[Apple Pro Res] An app may be able to cause unexpected system termination

N/A
CVE-2025-31247

[Apple SharedFileList] An attacker may gain access to protected parts of the file system

N/A
CVE-2025-31251

[Apple AppleJPEG] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process…

N/A