Official source evidencesupport.apple.comVersioned article
Official source article · support.apple.com

About the security content of macOS Sonoma 14.8.4 - Apple Support

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs50

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-28995A logic issue was addressed with improved restrictions
  • CVE-2025-46281A logic issue was addressed with improved checks
  • CVE-2026-20615A path handling issue was addressed with improved validation
  • CVE-2026-20696An authorization issue was addressed with improved state management
  • CVE-2025-43417A path handling issue was addressed with improved logic
  • CVE-2026-20622A privacy issue was addressed with improved handling of temporary files
  • CVE-2026-20617A race condition was addressed with improved state handling
  • CVE-2026-20677A shortcut may be able to bypass sandbox restrictions
  • CVE-2025-43473This issue was addressed with improved state management
  • CVE-2025-46283A logic issue was addressed with improved validation
  • CVE-2026-20627An issue existed in the handling of environment variables
  • CVE-2026-20670An authorization issue was addressed with improved state management
  • CVE-2026-20630A permissions issue was addressed with additional restrictions
  • CVE-2025-59375libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
  • CVE-2025-46310An attacker with root privileges may be able to delete protected system files
  • CVE-2025-43403An authorization issue was addressed with improved state management
  • CVE-2025-46304The issue was addressed with improved bounds checks
  • CVE-2026-20606This issue was addressed by removing the vulnerable code
  • CVE-2026-20605The issue was addressed with improved memory handling
  • CVE-2026-20625A parsing issue in the handling of directory paths was addressed with improved path validation
  • CVE-2026-20609The issue was addressed with improved memory handling
  • CVE-2026-20624An injection issue was addressed with improved validation
  • CVE-2026-20673A logic issue was addressed with improved checks
  • CVE-2026-20653A parsing issue in the handling of directory paths was addressed with improved path validation
  • CVE-2026-20612A privacy issue was addressed with improved checks
  • CVE-2026-20628A permissions issue was addressed with additional restrictions
  • CVE-2025-43338An out-of-bounds access issue was addressed with improved bounds checking
  • CVE-2025-46301The issue was addressed with improved bounds checks
  • CVE-2025-43533The issue was addressed with improved bounds checks
  • CVE-2026-20602The issue was addressed with improved handling of caches
  • CVE-2026-20614A path handling issue was addressed with improved validation
  • CVE-2026-20680The issue was addressed with additional restrictions on the observability of app states
  • CVE-2025-46290A remote attacker may be able to cause a denial-of-service
  • CVE-2025-46300The issue was addressed with improved bounds checks
  • CVE-2026-20634The issue was addressed with improved memory handling
  • CVE-2026-20675The issue was addressed with improved bounds checks
  • CVE-2025-46303The issue was addressed with improved bounds checks
  • CVE-2026-20660A path handling issue was addressed with improved logic
  • CVE-2026-20621The issue was addressed with improved memory handling
  • CVE-2025-43402The issue was addressed with improved memory handling
  • CVE-2026-20694This issue was addressed with improved handling of symlinks
  • CVE-2026-20616An out-of-bounds write issue was addressed with improved bounds checking
  • CVE-2026-20641A privacy issue was addressed with improved checks
  • CVE-2026-20620An attacker may be able to cause unexpected system termination or read kernel memory
  • CVE-2025-46302The issue was addressed with improved bounds checks
  • CVE-2026-20611An out-of-bounds access issue was addressed with improved bounds checking
  • CVE-2025-46305The issue was addressed with improved bounds checks
  • CVE-2026-20671An attacker in a privileged network position may be able to intercept network traffic
  • CVE-2026-20667A logic issue was addressed with improved checks
  • CVE-2026-20651A privacy issue was addressed with improved handling of temporary files

Source and provenance

Original title: About the security content of macOS Sonoma 14.8.4 - Apple Support. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗