macOS
macOS 15.6
Advisory officiel92 CVE corrigées par cette release.
- Date de sortie
- 2025-07-29
- Fin de support
- —
- CVE corrigées
- 92
- KEV CISA
- 2
- Critique
- 0
- Élevé
- 2
- En attente NVD
- 89
CVE corrigées
| CVE | Sévérité | KEV | Publié | Description |
|---|---|---|---|---|
|
CVE-2025-31277
KEV
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | KEV | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2025-6558
KEV
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash |
N/A | KEV | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash | |
|
CVE-2025-6965
[Apple SQLite] Processing a file may lead to memory corruption |
HIGH 9.8 | — | [Apple SQLite] Processing a file may lead to memory corruption | |
|
CVE-2025-7425
[Apple libxml2] Processing a file may lead to memory corruption |
HIGH 7.8 | — | [Apple libxml2] Processing a file may lead to memory corruption | |
|
CVE-2025-7424
[Apple libxslt] Processing maliciously crafted web content may lead to memory corruption |
MEDIUM 7.3 | — | [Apple libxslt] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2025-43273
[Apple CoreMedia] A sandboxed process may be able to circumvent sandbox restrictions |
N/A | — | [Apple CoreMedia] A sandboxed process may be able to circumvent sandbox restrictions | |
|
CVE-2025-43277
[Apple CoreAudio] Processing a maliciously crafted audio file may lead to memory corruption |
N/A | — | [Apple CoreAudio] Processing a maliciously crafted audio file may lead to memory corruption | |
|
CVE-2025-24188
[Apple Safari] Processing maliciously crafted web content may lead to an unexpected Safari crash |
N/A | — | [Apple Safari] Processing maliciously crafted web content may lead to an unexpected Safari crash | |
|
CVE-2025-31243
[Apple AppleMobileFileIntegrity] An app may be able to gain root privileges |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to gain root privileges | |
|
CVE-2025-31273
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2025-31275
[Apple MediaRemote] A sandboxed process may be able to launch any installed app |
N/A | — | [Apple MediaRemote] A sandboxed process may be able to launch any installed app | |
|
CVE-2025-31278
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2025-31279
[Apple Find My] An app may be able to fingerprint the user |
N/A | — | [Apple Find My] An app may be able to fingerprint the user | |
|
CVE-2025-31280
[Apple Model I/O] Processing a maliciously crafted file may lead to heap corruption |
N/A | — | [Apple Model I/O] Processing a maliciously crafted file may lead to heap corruption | |
|
CVE-2025-31281
[Apple Model I/O] Processing a maliciously crafted file may lead to unexpected app termination |
N/A | — | [Apple Model I/O] Processing a maliciously crafted file may lead to unexpected app termination | |
|
CVE-2025-43185
[Apple Voice Control] An app may be able to access protected user data |
N/A | — | [Apple Voice Control] An app may be able to access protected user data | |
|
CVE-2025-43186
[Apple afclip] Parsing a file may lead to an unexpected app termination |
N/A | — | [Apple afclip] Parsing a file may lead to an unexpected app termination | |
|
CVE-2025-43187
[Apple Disk Images] Running an hdiutil command may unexpectedly execute arbitrary code |
N/A | — | [Apple Disk Images] Running an hdiutil command may unexpectedly execute arbitrary code | |
|
CVE-2025-43188
[Apple DiskArbitration] A malicious app may be able to gain root privileges |
N/A | — | [Apple DiskArbitration] A malicious app may be able to gain root privileges | |
|
CVE-2025-43189
[Apple WebContentFilter] A malicious app may be able to read kernel memory |
N/A | — | [Apple WebContentFilter] A malicious app may be able to read kernel memory | |
|
CVE-2025-43191
[Apple Admin Framework] An app may be able to cause a denial-of-service |
N/A | — | [Apple Admin Framework] An app may be able to cause a denial-of-service | |
|
CVE-2025-43192
[Apple Managed Configuration] Account-driven User Enrollment may still be possible with Lockdown Mode turned on |
N/A | — | [Apple Managed Configuration] Account-driven User Enrollment may still be possible with Lockdown Mode turned on | |
|
CVE-2025-43193
[Apple SecurityAgent] An app may be able to cause a denial-of-service |
N/A | — | [Apple SecurityAgent] An app may be able to cause a denial-of-service | |
|
CVE-2025-43194
[Apple PackageKit] An app may be able to modify protected parts of the file system |
N/A | — | [Apple PackageKit] An app may be able to modify protected parts of the file system | |
|
CVE-2025-43195
[Apple CoreServices] An app may be able to access sensitive user data |
N/A | — | [Apple CoreServices] An app may be able to access sensitive user data | |
|
CVE-2025-43196
[Apple libxpc] An app may be able to gain root privileges |
N/A | — | [Apple libxpc] An app may be able to gain root privileges | |
|
CVE-2025-43197
[Apple Single Sign-On] An app may be able to access sensitive user data |
N/A | — | [Apple Single Sign-On] An app may be able to access sensitive user data | |
|
CVE-2025-43198
[Apple Dock] An app may be able to access protected user data |
N/A | — | [Apple Dock] An app may be able to access protected user data | |
|
CVE-2025-43199
[Apple Core Services] A malicious app may be able to gain root privileges |
N/A | — | [Apple Core Services] A malicious app may be able to gain root privileges | |
|
CVE-2025-43202
[Apple libnetcore] Processing a file may lead to memory corruption |
N/A | — | [Apple libnetcore] Processing a file may lead to memory corruption | |
|
CVE-2025-43206
[Apple System Settings] An app may be able to access protected user data |
N/A | — | [Apple System Settings] An app may be able to access protected user data | |
|
CVE-2025-43209
[Apple ICU] Processing maliciously crafted web content may lead to an unexpected Safari crash |
N/A | — | [Apple ICU] Processing maliciously crafted web content may lead to an unexpected Safari crash | |
|
CVE-2025-43210
[Apple CoreMedia] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process… |
N/A | — | [Apple CoreMedia] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory | |
|
CVE-2025-43211
[Apple WebKit] Processing web content may lead to a denial-of-service |
N/A | — | [Apple WebKit] Processing web content may lead to a denial-of-service | |
|
CVE-2025-43212
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash | |
|
CVE-2025-43213
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash | |
|
CVE-2025-43214
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash | |
|
CVE-2025-43215
[Apple Model I/O] Processing a maliciously crafted image may result in disclosure of process memory |
N/A | — | [Apple Model I/O] Processing a maliciously crafted image may result in disclosure of process memory | |
|
CVE-2025-43216
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash | |
|
CVE-2025-43218
[Apple Model I/O] Processing a maliciously crafted USD file may disclose memory contents |
N/A | — | [Apple Model I/O] Processing a maliciously crafted USD file may disclose memory contents | |
|
CVE-2025-43219
[Apple Model I/O] Processing a maliciously crafted image may corrupt process memory |
N/A | — | [Apple Model I/O] Processing a maliciously crafted image may corrupt process memory | |
|
CVE-2025-43220
[Apple copyfile] An app may be able to access protected user data |
N/A | — | [Apple copyfile] An app may be able to access protected user data | |
|
CVE-2025-43221
[Apple Model I/O] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process… |
N/A | — | [Apple Model I/O] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory | |
|
CVE-2025-43222
[Apple CFNetwork] An attacker may be able to cause unexpected app termination |
N/A | — | [Apple CFNetwork] An attacker may be able to cause unexpected app termination | |
|
CVE-2025-43223
[Apple CFNetwork] A non-privileged user may be able to modify restricted network settings |
N/A | — | [Apple CFNetwork] A non-privileged user may be able to modify restricted network settings | |
|
CVE-2025-43224
[Apple Model I/O] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process… |
N/A | — | [Apple Model I/O] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory | |
|
CVE-2025-43225
[Apple Notes] An app may be able to access sensitive user data |
N/A | — | [Apple Notes] An app may be able to access sensitive user data | |
|
CVE-2025-43226
[Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory |
N/A | — | [Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory | |
|
CVE-2025-43227
[Apple WebKit] Processing maliciously crafted web content may disclose sensitive user information |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may disclose sensitive user information | |
|
CVE-2025-43229
[Apple WebKit] Processing maliciously crafted web content may lead to universal cross site scripting |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to universal cross site scripting | |
|
CVE-2025-43230
[Apple CoreMedia Playback] An app may be able to access user-sensitive data |
N/A | — | [Apple CoreMedia Playback] An app may be able to access user-sensitive data | |
|
CVE-2025-43232
[Apple PackageKit] An app may be able to bypass certain Privacy preferences |
N/A | — | [Apple PackageKit] An app may be able to bypass certain Privacy preferences | |
|
CVE-2025-43233
[Apple Security] A malicious app acting as a HTTPS proxy could get access to sensitive user data |
N/A | — | [Apple Security] A malicious app acting as a HTTPS proxy could get access to sensitive user data | |
|
CVE-2025-43234
[Apple Metal] Processing a maliciously crafted texture may lead to unexpected app termination |
N/A | — | [Apple Metal] Processing a maliciously crafted texture may lead to unexpected app termination | |
|
CVE-2025-43235
[Apple Power Management] An app may be able to cause a denial-of-service |
N/A | — | [Apple Power Management] An app may be able to cause a denial-of-service | |
|
CVE-2025-43236
[Apple Power Management] An attacker may be able to cause unexpected app termination |
N/A | — | [Apple Power Management] An attacker may be able to cause unexpected app termination | |
|
CVE-2025-43237
[Apple WebContentFilter] An app may be able to cause unexpected system termination |
N/A | — | [Apple WebContentFilter] An app may be able to cause unexpected system termination | |
|
CVE-2025-43238
[Apple Xsan] An app may be able to cause unexpected system termination |
N/A | — | [Apple Xsan] An app may be able to cause unexpected system termination | |
|
CVE-2025-43239
[Apple sips] Processing a maliciously crafted file may lead to unexpected app termination |
N/A | — | [Apple sips] Processing a maliciously crafted file may lead to unexpected app termination | |
|
CVE-2025-43240
[Apple WebKit] A download's origin may be incorrectly associated |
N/A | — | [Apple WebKit] A download's origin may be incorrectly associated | |
|
CVE-2025-43241
[Apple SceneKit] An app may be able to read files outside of its sandbox |
N/A | — | [Apple SceneKit] An app may be able to read files outside of its sandbox | |
|
CVE-2025-43243
[Apple Software Update] An app may be able to modify protected parts of the file system |
N/A | — | [Apple Software Update] An app may be able to modify protected parts of the file system | |
|
CVE-2025-43244
[Apple AMD] An app may be able to cause unexpected system termination |
N/A | — | [Apple AMD] An app may be able to cause unexpected system termination | |
|
CVE-2025-43245
[Apple AppleMobileFileIntegrity] An app may be able to access protected user data |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to access protected user data | |
|
CVE-2025-43246
[Apple Spotlight] An app may be able to access sensitive user data |
N/A | — | [Apple Spotlight] An app may be able to access sensitive user data | |
|
CVE-2025-43247
[Apple PackageKit] A malicious app with root privileges may be able to modify the contents of system files |
N/A | — | [Apple PackageKit] A malicious app with root privileges may be able to modify the contents of system files | |
|
CVE-2025-43248
[Apple AppleMobileFileIntegrity] A malicious app may be able to gain root privileges |
N/A | — | [Apple AppleMobileFileIntegrity] A malicious app may be able to gain root privileges | |
|
CVE-2025-43249
[Apple AppleMobileFileIntegrity] An app may be able to gain root privileges |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to gain root privileges | |
|
CVE-2025-43250
[Apple SharedFileList] An app may be able to break out of its sandbox |
N/A | — | [Apple SharedFileList] An app may be able to break out of its sandbox | |
|
CVE-2025-43251
[Apple User Management] A local attacker may gain access to Keychain items |
N/A | — | [Apple User Management] A local attacker may gain access to Keychain items | |
|
CVE-2025-43252
[Apple zip] A website may be able to access sensitive user data when resolving symlinks |
N/A | — | [Apple zip] A website may be able to access sensitive user data when resolving symlinks | |
|
CVE-2025-43253
[Apple AppleMobileFileIntegrity] A malicious app may be able to launch arbitrary binaries on a trusted device |
N/A | — | [Apple AppleMobileFileIntegrity] A malicious app may be able to launch arbitrary binaries on a trusted device | |
|
CVE-2025-43254
[Apple file] Processing a maliciously crafted file may lead to unexpected app termination |
N/A | — | [Apple file] Processing a maliciously crafted file may lead to unexpected app termination | |
|
CVE-2025-43255
[Apple GPU Drivers] An app may be able to cause unexpected system termination |
N/A | — | [Apple GPU Drivers] An app may be able to cause unexpected system termination | |
|
CVE-2025-43256
[Apple StorageKit] An app may be able to gain root privileges |
N/A | — | [Apple StorageKit] An app may be able to gain root privileges | |
|
CVE-2025-43257
[Apple Archive Utility] An app may be able to break out of its sandbox |
N/A | — | [Apple Archive Utility] An app may be able to break out of its sandbox | |
|
CVE-2025-43259
[Apple WindowServer] An attacker with physical access to a locked device may be able to view sensitive user information |
N/A | — | [Apple WindowServer] An attacker with physical access to a locked device may be able to view sensitive user information | |
|
CVE-2025-43260
[Apple PackageKit] An app may be able to hijack entitlements granted to other privileged apps |
N/A | — | [Apple PackageKit] An app may be able to hijack entitlements granted to other privileged apps | |
|
CVE-2025-43261
[Apple File Bookmark] An app may be able to break out of its sandbox |
N/A | — | [Apple File Bookmark] An app may be able to break out of its sandbox | |
|
CVE-2025-43264
[Apple Model I/O] Processing a maliciously crafted image may corrupt process memory |
N/A | — | [Apple Model I/O] Processing a maliciously crafted image may corrupt process memory | |
|
CVE-2025-43265
[Apple WebKit] Processing maliciously crafted web content may disclose internal states of the app |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may disclose internal states of the app | |
|
CVE-2025-43266
[Apple NSSpellChecker] An app may be able to break out of its sandbox |
N/A | — | [Apple NSSpellChecker] An app may be able to break out of its sandbox | |
|
CVE-2025-43267
[Apple Directory Utility] An app may be able to access sensitive user data |
N/A | — | [Apple Directory Utility] An app may be able to access sensitive user data | |
|
CVE-2025-43268
[Apple Kernel] A malicious app may be able to gain root privileges |
N/A | — | [Apple Kernel] A malicious app may be able to gain root privileges | |
|
CVE-2025-43270
[Apple Notes] An app may gain unauthorized access to Local Network |
N/A | — | [Apple Notes] An app may gain unauthorized access to Local Network | |
|
CVE-2025-43274
[Apple RemoteViewServices] A sandboxed process may be able to circumvent sandbox restrictions |
N/A | — | [Apple RemoteViewServices] A sandboxed process may be able to circumvent sandbox restrictions | |
|
CVE-2025-43275
[Apple NetAuth] An app may be able to break out of its sandbox |
N/A | — | [Apple NetAuth] An app may be able to break out of its sandbox | |
|
CVE-2025-43276
[Apple Kernel] iCloud Private Relay may not activate when more than one user is logged in at the same time |
N/A | — | [Apple Kernel] iCloud Private Relay may not activate when more than one user is logged in at the same time | |
|
CVE-2025-43281
[Apple Application Firewall] A local attacker may be able to elevate their privileges |
N/A | — | [Apple Application Firewall] A local attacker may be able to elevate their privileges | |
|
CVE-2025-43282
[Apple Kernel] An app may be able to cause unexpected system termination |
N/A | — | [Apple Kernel] An app may be able to cause unexpected system termination | |
|
CVE-2025-43284
[Apple GPU Drivers] An app may be able to cause unexpected system termination |
N/A | — | [Apple GPU Drivers] An app may be able to cause unexpected system termination | |
|
CVE-2025-43313
[Apple CoreServices] An app may be able to access sensitive user data |
N/A | — | [Apple CoreServices] An app may be able to access sensitive user data |