BlackTreeCVE IntelligenceOfficial source evidencesupport.apple.comVersioned article
Official source article · support.apple.com
About the security content of macOS Sonoma 14.8.4 - Apple Support
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 02:41 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-28995A logic issue was addressed with improved restrictions
- CVE-2025-46281A logic issue was addressed with improved checks
- CVE-2026-20615A path handling issue was addressed with improved validation
- CVE-2026-20696An authorization issue was addressed with improved state management
- CVE-2025-43417A path handling issue was addressed with improved logic
- CVE-2026-20622A privacy issue was addressed with improved handling of temporary files
- CVE-2026-20617A race condition was addressed with improved state handling
- CVE-2026-20677A shortcut may be able to bypass sandbox restrictions
- CVE-2025-43473This issue was addressed with improved state management
- CVE-2025-46283A logic issue was addressed with improved validation
- CVE-2026-20627An issue existed in the handling of environment variables
- CVE-2026-20670An authorization issue was addressed with improved state management
- CVE-2026-20630A permissions issue was addressed with additional restrictions
- CVE-2025-59375libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
- CVE-2025-46310An attacker with root privileges may be able to delete protected system files
- CVE-2025-43403An authorization issue was addressed with improved state management
- CVE-2025-46304The issue was addressed with improved bounds checks
- CVE-2026-20606This issue was addressed by removing the vulnerable code
- CVE-2026-20605The issue was addressed with improved memory handling
- CVE-2026-20625A parsing issue in the handling of directory paths was addressed with improved path validation
- CVE-2026-20609The issue was addressed with improved memory handling
- CVE-2026-20624An injection issue was addressed with improved validation
- CVE-2026-20673A logic issue was addressed with improved checks
- CVE-2026-20653A parsing issue in the handling of directory paths was addressed with improved path validation
- CVE-2026-20612A privacy issue was addressed with improved checks
- CVE-2026-20628A permissions issue was addressed with additional restrictions
- CVE-2025-43338An out-of-bounds access issue was addressed with improved bounds checking
- CVE-2025-46301The issue was addressed with improved bounds checks
- CVE-2025-43533The issue was addressed with improved bounds checks
- CVE-2026-20602The issue was addressed with improved handling of caches
- CVE-2026-20614A path handling issue was addressed with improved validation
- CVE-2026-20680The issue was addressed with additional restrictions on the observability of app states
- CVE-2025-46290A remote attacker may be able to cause a denial-of-service
- CVE-2025-46300The issue was addressed with improved bounds checks
- CVE-2026-20634The issue was addressed with improved memory handling
- CVE-2026-20675The issue was addressed with improved bounds checks
- CVE-2025-46303The issue was addressed with improved bounds checks
- CVE-2026-20660A path handling issue was addressed with improved logic
- CVE-2026-20621The issue was addressed with improved memory handling
- CVE-2025-43402The issue was addressed with improved memory handling
- CVE-2026-20694This issue was addressed with improved handling of symlinks
- CVE-2026-20616An out-of-bounds write issue was addressed with improved bounds checking
- CVE-2026-20641A privacy issue was addressed with improved checks
- CVE-2026-20620An attacker may be able to cause unexpected system termination or read kernel memory
- CVE-2025-46302The issue was addressed with improved bounds checks
- CVE-2026-20611An out-of-bounds access issue was addressed with improved bounds checking
- CVE-2025-46305The issue was addressed with improved bounds checks
- CVE-2026-20671An attacker in a privileged network position may be able to intercept network traffic
- CVE-2026-20667A logic issue was addressed with improved checks
- CVE-2026-20651A privacy issue was addressed with improved handling of temporary files
Source and provenance
Original title: About the security content of macOS Sonoma 14.8.4 - Apple Support. Captured 29 Sept 2026, 02:41 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗