Skip to content
Appaloosa Scout

macOS

87 CVEs fixed by this release.

Release date
2025-09-15
End of support
CVEs fixed
87
CISA KEV
0
Critical
0
High
1
NVD pending
84

CVEs fixed

CVE Severity
CVE-2025-6965

[Apple SQLite] Processing a file may lead to memory corruption

HIGH 9.8
CVE-2025-40909

[Apple Perl] Multiple issues in Perl

MEDIUM 5.9
CVE-2025-46306

The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS T…

MEDIUM 5.5
CVE-2025-43376

[Apple WebKit] A remote attacker may be able to view leaked DNS queries with Private Relay turned on

N/A
CVE-2025-43338

[Apple ImageIO] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process m…

N/A
CVE-2025-43320

[Apple AppleMobileFileIntegrity] An app may be able to bypass launch constraint protections and execute malicious code …

N/A
CVE-2025-43292

[Apple CoreMedia] An app may be able to access sensitive user data

N/A
CVE-2025-43294

[Apple MallocStackLogging] An app may be able to access sensitive user data

N/A
CVE-2025-43337

[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data

N/A
CVE-2025-43361

[Apple Audio] A malicious app may be able to read kernel memory

N/A
CVE-2025-43372

[Apple CoreMedia] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process…

N/A
CVE-2024-27280

[Apple Ruby] Processing a file may lead to a denial-of-service or potentially disclose memory contents

N/A
CVE-2025-24088

[Apple CoreServices] An app may be able to override MDM-enforced settings from profiles

N/A
CVE-2025-24197

[Apple Spotlight] An app may be able to access sensitive user data

N/A
CVE-2025-31255

[Apple IOKit] An app may be able to access sensitive user data

N/A
CVE-2025-31259

[Apple SoftwareUpdate] An app may be able to gain elevated privileges

N/A
CVE-2025-31268

[Apple Apple Online Store Kit] An app may be able to access protected user data

N/A
CVE-2025-31269

[Apple Printing] An app may be able to access protected user data

N/A
CVE-2025-31270

[Apple Foundation] An app may be able to access protected user data

N/A
CVE-2025-31271

[Apple FaceTime] Incoming FaceTime calls can appear or be accepted on a locked macOS device, even with notifications di…

N/A
CVE-2025-43190

[Apple Spell Check] An app may be able to access sensitive user data

N/A
CVE-2025-43204

[Apple RemoteViewServices] An app may be able to break out of its sandbox

N/A
CVE-2025-43207

[Apple Music] An app may be able to access user-sensitive data

N/A
CVE-2025-43208

[Apple AirPort] An app may be able to read sensitive location information

N/A
CVE-2025-43262

[Apple Trusted Device] USB Restricted Mode may not be applied to accessories connected during boot

N/A
CVE-2025-43272

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected Safari crash

N/A
CVE-2025-43279

[Apple Notification Center] An app may be able to access user-sensitive data

N/A
CVE-2025-43283

[Apple GPU Drivers] An app may be able to cause unexpected system termination

N/A
CVE-2025-43285

[Apple AppSandbox] An app may be able to access protected user data

N/A
CVE-2025-43286

[Apple SharedFileList] An app may be able to break out of its sandbox

N/A
CVE-2025-43287

[Apple ImageIO] Processing a maliciously crafted image may corrupt process memory

N/A
CVE-2025-43288

[Apple Archive Utility] An app may be able to bypass Privacy preferences

N/A
CVE-2025-43291

[Apple SharedFileList] An app may be able to modify protected parts of the file system

N/A
CVE-2025-43293

[Apple SharedFileList] An app may be able to access sensitive user data

N/A
CVE-2025-43295

[Apple libc] An app may be able to cause a denial-of-service

N/A
CVE-2025-43296

[Apple System Settings] An app may bypass Gatekeeper checks

N/A
CVE-2025-43297

[Apple Power Management] An app may be able to cause a denial-of-service

N/A
CVE-2025-43298

[Apple PackageKit] An app may be able to gain root privileges

N/A
CVE-2025-43299

[Apple libc] An app may be able to cause a denial-of-service

N/A
CVE-2025-43301

[Apple Notification Center] An app may be able to access contact info related to notifications in Notification Center

N/A
CVE-2025-43302

[Apple IOHIDFamily] An app may be able to cause unexpected system termination

N/A
CVE-2025-43303

[Apple Bluetooth] An app may be able to access sensitive user data

N/A
CVE-2025-43304

[Apple StorageKit] An app may be able to gain root privileges

N/A
CVE-2025-43305

[Apple CoreServices] A malicious app may be able to access private information

N/A
CVE-2025-43307

[Apple Bluetooth] An app may be able to access sensitive user data

N/A
CVE-2025-43308

[Apple Touch Bar Controls] An app may be able to access sensitive user data

N/A
CVE-2025-43310

[Apple WindowServer] An app may be able to trick a user into copying sensitive data to the pasteboard

N/A
CVE-2025-43311

[Apple Touch Bar] An app may be able to access protected user data

N/A
CVE-2025-43312

[Apple AMD] An app may be able to cause unexpected system termination

N/A
CVE-2025-43314

[Apple StorageKit] An app may be able to access sensitive user data

N/A
CVE-2025-43315

[Apple MigrationKit] An app may be able to access user-sensitive data

N/A
CVE-2025-43316

[Apple DiskArbitration] A malicious app may be able to gain root privileges

N/A
CVE-2025-43317

[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data

N/A
CVE-2025-43318

[Apple Sandbox] An app with root privileges may be able to access private information

N/A
CVE-2025-43319

[Apple MediaLibrary] An app may be able to access protected user data

N/A
CVE-2025-43321

[Apple AppKit] An app may be able to access protected user data

N/A
CVE-2025-43323

[Apple CloudKit] An app may be able to fingerprint the user

N/A
CVE-2025-43325

[Apple Icons] An app may be able to access sensitive user data

N/A
CVE-2025-43326

[Apple GPU Drivers] An app may be able to access sensitive user data

N/A
CVE-2025-43327

[Apple Safari] Visiting a malicious website may lead to address bar spoofing

N/A
CVE-2025-43328

[Apple Sandbox] An app may be able to access sensitive user data

N/A
CVE-2025-43329

[Apple Sandbox] An app may be able to break out of its sandbox

N/A
CVE-2025-43330

[Apple ATS] An app may be able to break out of its sandbox

N/A
CVE-2025-43331

[Apple AppleMobileFileIntegrity] An app may be able to access protected user data

N/A
CVE-2025-43332

[Apple Security Initialization] An app may be able to break out of its sandbox

N/A
CVE-2025-43333

[Apple Spotlight] An app may be able to gain root privileges

N/A
CVE-2025-43340

[Apple AppleMobileFileIntegrity] An app may be able to break out of its sandbox

N/A
CVE-2025-43341

[Apple Storage] An app may be able to gain root privileges

N/A
CVE-2025-43342

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2025-43343

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2025-43344

[Apple Apple Neural Engine] An app may be able to cause unexpected system termination

N/A
CVE-2025-43345

[Apple Kernel] An app may be able to access sensitive user data

N/A
CVE-2025-43346

[Apple Audio] Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process mem…

N/A
CVE-2025-43347

[Apple System] An input validation issue was addressed

N/A
CVE-2025-43349

[Apple CoreAudio] Processing a maliciously crafted video file may lead to unexpected app termination

N/A
CVE-2025-43353

[Apple Libinfo] Processing a maliciously crafted string may lead to heap corruption

N/A
CVE-2025-43354

[Apple Bluetooth] An app may be able to access sensitive user data

N/A
CVE-2025-43355

[Apple MobileStorageMounter] An app may be able to cause a denial-of-service

N/A
CVE-2025-43356

[Apple WebKit] A website may be able to access sensor information without user consent

N/A
CVE-2025-43357

[Apple Call History] An app may be able to fingerprint the user

N/A
CVE-2025-43358

[Apple Shortcuts] A shortcut may be able to bypass sandbox restrictions

N/A
CVE-2025-43359

[Apple Kernel] A UDP server socket bound to a local interface may become bound to all interfaces

N/A
CVE-2025-43366

[Apple IOMobileFrameBuffer] An app may be able to disclose coprocessor memory

N/A
CVE-2025-43367

[Apple Siri] An app may be able to access protected user data

N/A
CVE-2025-43368

[Apple WebKit Process Model] Processing maliciously crafted web content may lead to an unexpected Safari crash

N/A
CVE-2025-43369

[Apple SharedFileList] An app may be able to access protected user data

N/A
CVE-2025-43419

[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption

N/A