macOS 15.x — End of Life

Active High risk
1 release in this series54 CVEs

macOS 15.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
15Sep 16, 2024No15.7.7Active

CVEs affecting macOS 15.x (54)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2025-43524HIGH8.80.01%15An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS S…May 12, 2026
CVE-2026-28978HIGH8.80.01%15A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom…May 11, 2026
CVE-2026-28923HIGH8.80.01%15A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14…May 11, 2026
CVE-2026-28940HIGH8.80.05%15The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and…May 11, 2026
CVE-2026-28919HIGH7.80.01%15A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom…May 11, 2026
CVE-2026-28915HIGH7.80.02%15A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m…May 11, 2026
CVE-2026-28840HIGH7.80.01%15A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom…May 11, 2026
CVE-2025-43306HIGH7.80.01%15A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta…May 26, 2026
CVE-2026-28951HIGH7.80.01%15An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9…May 11, 2026
CVE-2026-43668HIGH7.50.16%15A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.…May 11, 2026
CVE-2026-28924HIGH7.50.04%15A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, ma…May 11, 2026
CVE-2026-28925HIGH7.50.04%15A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma…May 11, 2026
CVE-2026-28929HIGH7.50.04%15A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.…May 11, 2026
CVE-2026-28943HIGH7.50.05%15A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.…May 11, 2026
CVE-2026-28952HIGH7.50.02%15An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, m…May 11, 2026
CVE-2026-28954HIGH7.50.04%15A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macO…May 11, 2026
CVE-2026-28959HIGH7.50.08%15A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS …May 11, 2026
CVE-2026-28969HIGH7.50.05%15A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.…May 11, 2026
CVE-2026-28987HIGH7.50.05%15A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.…May 11, 2026
CVE-2026-43654HIGH7.50.05%15The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and…May 11, 2026
CVE-2026-39871HIGH7.50.04%15A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.…May 11, 2026
CVE-2026-39870HIGH7.50.04%15The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7,…May 11, 2026
CVE-2026-28846HIGH7.50.18%15A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS …May 11, 2026
CVE-2026-28848HIGH7.50.11%15A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe …May 11, 2026
CVE-2026-28860HIGH7.50.12%15The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 an…May 11, 2026
CVE-2026-28906HIGH7.50.05%15This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.…May 11, 2026
CVE-2026-28908HIGH7.50.05%15A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, ma…May 11, 2026
CVE-2026-28974HIGH7.50.05%15This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadO…May 11, 2026
CVE-2026-28986HIGH7.50.06%15A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5…May 11, 2026
CVE-2026-28990HIGH7.50.05%15The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15…May 11, 2026
CVE-2026-43656HIGH7.30.07%15An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS …May 11, 2026
CVE-2026-28941HIGH7.10.04%15The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7,…May 11, 2026
CVE-2025-46284HIGH7.00.01%15A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An…May 26, 2026
CVE-2026-28920MEDIUM6.50.05%15An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iO…May 11, 2026
CVE-2026-28922MEDIUM6.50.03%15This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14…May 11, 2026
CVE-2026-28956MEDIUM6.50.04%15A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5,…May 11, 2026
CVE-2026-28972MEDIUM6.50.06%15An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS …May 11, 2026
CVE-2026-28897MEDIUM6.20.01%15A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS…May 11, 2026
CVE-2026-28977MEDIUM6.20.01%15The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and i…May 11, 2026
CVE-2026-43666MEDIUM6.20.01%15An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1…May 11, 2026
CVE-2025-46307MEDIUM5.50.01%15A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to acc…May 26, 2026
CVE-2026-28993MEDIUM5.50.01%15This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 1…May 11, 2026
CVE-2026-20696MEDIUM5.50.01%15An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may…May 11, 2026
CVE-2025-43289MEDIUM5.50.01%15A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macO…May 26, 2026
CVE-2025-43290MEDIUM5.50.00%15A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma …May 26, 2026
CVE-2025-43451MEDIUM5.50.01%15A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be …May 26, 2026
CVE-2025-46280MEDIUM5.50.01%15An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be …May 26, 2026
CVE-2026-28996MEDIUM5.50.01%15A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoi…May 11, 2026
CVE-2026-28819MEDIUM5.40.05%15An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1…May 11, 2026
CVE-2026-28994MEDIUM5.30.03%15A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.…May 11, 2026
CVE-2026-28992MEDIUM4.70.01%15A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7…May 11, 2026
CVE-2026-43659MEDIUM4.70.01%15A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5…May 11, 2026
CVE-2026-28830MEDIUM4.70.01%15A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able t…May 11, 2026
CVE-2026-39869MEDIUM4.30.04%15The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and…May 11, 2026

macOS 15.x will reach end of life — migrate to macOS 26.x

macOS 26.x is the next major release. Plan your upgrade before macOS 15.x stops receiving security patches.

See macOS 26.x

Frequently asked questions

Is macOS 15 end of life?

No. macOS 15.x is still supported. It continues to receive security patches and bug fixes.

What CVEs affect macOS 15?

There are 54 CVEs tracked for macOS 15.x. See the full list above with CVSS and EPSS scores.

What is the latest macOS 15 version?

The latest macOS 15.x patch release is 15.7.7, released on May 11, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from macOS 15 to macOS 26?

To migrate from macOS 15 to macOS 26: (1) review the official macOS 26 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run macOS 15 in production?

macOS 15 is still supported and safe for production use. Ensure you are running the latest patch version (15.7.7) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA