BlackTreeCVE IntelligenceOfficial source evidencesupport.apple.comVersioned article
Official source article · support.apple.com
About the security content of macOS Sonoma 14.7.5 - Apple Support
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishersupport.apple.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 14:38 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2025-31197An attacker on the local network may cause an unexpected app termination
- CVE-2025-24179An attacker on the local network may be able to cause a denial-of-service
- CVE-2025-24270This issue was addressed by removing the vulnerable code
- CVE-2025-24271An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing
- CVE-2025-24251An attacker on the local network may cause an unexpected app termination
- CVE-2025-30470A path handling issue was addressed with improved logic
- CVE-2024-40864An attacker in a privileged network position may be able to track a user's activity
- CVE-2025-24235A remote attacker may be able to cause unexpected app termination or heap corruption
- CVE-2025-24278This issue was addressed with improved validation of symlinks
- CVE-2025-30446A permissions issue was addressed with additional restrictions
- CVE-2025-31191This issue was addressed through improved state management
- CVE-2025-30447The issue was resolved by sanitizing logging
- CVE-2025-24280An access issue was addressed with additional sandbox restrictions
- CVE-2025-24279This issue was addressed with improved file handling
- CVE-2025-24097A permissions issue was addressed with additional restrictions
- CVE-2025-24259This issue was addressed with additional entitlement checks
- CVE-2025-24233A permissions issue was addressed with additional restrictions
- CVE-2025-24232This issue was addressed through improved state management
- CVE-2025-24265An out-of-bounds read was addressed with improved bounds checking
- CVE-2025-24273An out-of-bounds write issue was addressed with improved bounds checking
- CVE-2025-24199An uncontrolled format string issue was addressed with improved input validation
- CVE-2025-24249A permissions issue was addressed with additional sandbox restrictions
- CVE-2025-30457This issue was addressed with improved validation of symlinks
- CVE-2025-24253This issue was addressed with improved handling of symlinks
- CVE-2025-24212This issue was addressed with improved checks
- CVE-2025-31183The issue was addressed with improved restriction of data container access
- CVE-2025-30454A path handling issue was addressed with improved validation
- CVE-2025-24250A malicious app acting as a HTTPS proxy could get access to sensitive user data
- CVE-2025-24196An attacker with user privileges may be able to read kernel memory
- CVE-2025-24207A permissions issue was addressed with additional restrictions
- CVE-2025-24211This issue was addressed with improved memory handling
- CVE-2025-24246An injection issue was addressed with improved validation
- CVE-2025-24231The issue was addressed with improved checks
- CVE-2025-24266A buffer overflow was addressed with improved bounds checking
- CVE-2025-30462A library injection issue was addressed with additional restrictions
- CVE-2025-24267A permissions issue was addressed with additional restrictions
- CVE-2025-24230An out-of-bounds read issue was addressed with improved input validation
- CVE-2025-24181A permissions issue was addressed with additional restrictions
- CVE-2025-24247An attacker may be able to cause unexpected app termination
- CVE-2025-24210A logic error was addressed with improved error handling
- CVE-2025-24178This issue was addressed through improved state management
- CVE-2025-30455The issue was addressed with improved checks
- CVE-2025-31182This issue was addressed with improved handling of symlinks
- CVE-2025-30443A privacy issue was addressed by removing the vulnerable code
- CVE-2025-31194An authentication issue was addressed with improved state management
- CVE-2025-24237A buffer overflow was addressed with improved bounds checking
- CVE-2025-24260An attacker in a privileged position may be able to perform a denial-of-service
- CVE-2025-30433This issue was addressed with improved access restrictions
- CVE-2025-30444A race condition was addressed with improved locking
- CVE-2025-30452The issue was addressed with improved checks
Source and provenance
Original title: About the security content of macOS Sonoma 14.7.5 - Apple Support. Captured 29 Sept 2026, 14:38 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗