Apple Tvos16.2 vulnerabilities

32 known vulnerabilities affecting apple/tvos16.2.

Total CVEs
32
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH21MEDIUM9

Vulnerabilities

Page 2 of 2
CVE-2022-48618HIGHCVSS 7.0KEV2022-12-13
CVE-2022-48618 [HIGH] CVE-2022-48618: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-48618 Component: Kernel Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1. Description: The issue was addressed with improved checks.
apple
CVE-2022-42849HIGHCVSS 7.82022-12-13
CVE-2022-42849 [HIGH] CVE-2022-42849: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-42849 Component: Software Update Impact: A user may be able to elevate privileges Description: An access issue existed with privileged API calls. This issue was addressed with additional restrictions.
apple
CVE-2022-42848HIGHCVSS 7.82022-12-13
CVE-2022-42848 [HIGH] CVE-2022-42848: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-42848 Component: AVEVideoEncoder Impact: An app may be able to execute arbitrary code with kernel privileges Description: A logic issue was addressed with improved checks.
apple
CVE-2022-42865MEDIUMCVSS 5.52022-12-13
CVE-2022-42865 [MEDIUM] CVE-2022-42865: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-42865 Component: AppleMobileFileIntegrity Impact: An app may be able to bypass Privacy preferences Description: This issue was addressed by enabling hardened runtime.
apple
CVE-2022-46695MEDIUMCVSS 6.52022-12-13
CVE-2022-46695 [MEDIUM] CVE-2022-46695: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-46695 Component: Safari Impact: Visiting a website that frames malicious content may lead to UI spoofing Description: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
apple
CVE-2022-42852MEDIUMCVSS 6.52022-12-13
CVE-2022-42852 [MEDIUM] CVE-2022-42852: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-42852 Component: WebKit Impact: Processing maliciously crafted web content may result in the disclosure of process memory Description: The issue was addressed with improved memory handling.
apple
CVE-2022-42851MEDIUMCVSS 5.52022-12-13
CVE-2022-42851 [MEDIUM] CVE-2022-42851: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-42851 Component: ImageIO Impact: Parsing a maliciously crafted TIFF file may lead to disclosure of user information Description: The issue was addressed with improved memory handling.
apple
CVE-2022-46692MEDIUMCVSS 5.52022-12-13
CVE-2022-46692 [MEDIUM] CVE-2022-46692: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-46692 Component: WebKit Impact: Processing maliciously crafted web content may bypass Same Origin Policy Description: A logic issue was addressed with improved state management.
apple
CVE-2022-46698MEDIUMCVSS 6.52022-12-13
CVE-2022-46698 [MEDIUM] CVE-2022-46698: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-46698 Component: WebKit Impact: Processing maliciously crafted web content may disclose sensitive user information Description: A logic issue was addressed with improved checks.
apple
CVE-2022-42866MEDIUMCVSS 5.52022-12-13
CVE-2022-42866 [MEDIUM] CVE-2022-42866: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-42866 Component: Weather Impact: An app may be able to read sensitive location information Description: The issue was addressed with improved handling of caches.
apple
CVE-2022-46705MEDIUMCVSS 4.32022-12-13
CVE-2022-46705 [MEDIUM] CVE-2022-46705: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-46705 Component: WebKit Impact: Visiting a malicious website may lead to address bar spoofing Description: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.
apple
CVE-2022-42843MEDIUMCVSS 5.52022-12-13
CVE-2022-42843 [MEDIUM] CVE-2022-42843: tvOS16.2 Apple Security Update: About the security content of tvOS16.2 Product: tvOS16.2 CVE: CVE-2022-42843 Component: Accounts Impact: A user may be able to view sensitive user information Description: This issue was addressed with improved data protection.
apple
Apple Tvos16.2 vulnerabilities | cvebase