Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68
Vulnerabilities
Page 1 of 119
CVE-2025-24085P1CRITICALCVSS 10.0KEVPoCfixed in 18.32025-01-27
CVE-2025-24085 [CRITICAL] CWE-416 CVE-2025-24085: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have be
nvdapple
CVE-2025-14174P1HIGHCVSS 8.8KEVPoCfixed in 26.2fixed in 26.32025-12-12
CVE-2025-14174 [HIGH] CWE-787 CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remot
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvdapple
CVE-2019-8506P1HIGHCVSS 8.8KEVPoCfixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8506 [HIGH] CWE-843 CVE-2019-8506: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2,
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2025-43529P1HIGHCVSS 8.8KEVPoCfixed in 26.22025-12-17
CVE-2025-43529 [HIGH] CVE-2025-43529: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been expl
nvdapple
CVE-2024-23222P1HIGHCVSS 8.8KEVPoCfixed in 17.32024-01-23
CVE-2024-23222 [HIGH] CWE-843 CVE-2024-23222: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 1
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2014-4404P1HIGHCVSS 7.8KEVPoCfixed in 7.02014-09-18
CVE-2014-4404 [HIGH] CWE-787 CVE-2014-4404: Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attacke
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.
nvd
CVE-2025-6558P1HIGHCVSS 8.8KEVPoCv18.62025-07-29
CVE-2025-6558 [HIGH] CVE-2025-6558: tvOS 18.6
Apple Security Update: About the security content of tvOS 18.6
Product: tvOS
Version: 18.6
CVE: CVE-2025-6558
Component: WebKit
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
apple
CVE-2019-8605P1HIGHCVSS 7.8KEVPoCfixed in 12.3≥ unspecified, < tvOS 12.32019-12-18
CVE-2019-8605 [HIGH] CWE-416 CVE-2019-8605: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
nvdapple
CVE-2021-30883P1HIGHCVSS 7.8KEVPoCfixed in 15.12021-08-24
CVE-2021-30883 [HIGH] CWE-787 CVE-2021-30883: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have b
nvdapple
CVE-2020-3837P1HIGHCVSS 7.8KEVPoCfixed in 13.3.1≥ unspecified, < tvOS 13.3.12020-02-27
CVE-2020-3837 [HIGH] CWE-787 CVE-2020-3837: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2019-7286P1HIGHCVSS 7.8KEVPoCv12.22019-03-25
CVE-2019-7286 [HIGH] CVE-2019-7286: tvOS 12.2
Apple Security Update: About the security content of tvOS 12.2
Product: tvOS
Version: 12.2
CVE: CVE-2019-7286
Component: Foundation
Impact: An application may be able to gain elevated privileges
Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2022-2294P1HIGHCVSS 8.8KEVRansomwarefixed in 15.62022-07-28
CVE-2022-2294 [HIGH] CWE-787 CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-20700P1HIGHCVSS 7.8KEVPoCfixed in 26.32026-02-11
CVE-2026-20700 [HIGH] CVE-2026-20700: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 2
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attac
nvdapple
CVE-2021-1782P1HIGHCVSS 7.0KEVPoCfixed in 14.42021-04-02
CVE-2021-1782 [HIGH] CWE-667 CVE-2021-1782: A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Sec
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2025-31200P1CRITICALCVSS 9.8KEVfixed in 18.4.12025-04-16
CVE-2025-31200 [CRITICAL] CWE-119 CVE-2025-31200: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited
nvdapple
CVE-2023-37450P1HIGHCVSS 8.8KEVfixed in 16.6≥ unspecified, < 16.62023-07-27
CVE-2023-37450 [HIGH] CVE-2023-37450: The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safar
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
nvdapple
CVE-2023-32373P1HIGHCVSS 8.8KEVfixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32373 [HIGH] CWE-416 CVE-2023-32373: A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively
nvdapple
CVE-2025-31201P1CRITICALCVSS 9.8KEVfixed in 18.4.12025-04-16
CVE-2025-31201 [CRITICAL] CWE-1220 CVE-2025-31201: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPad
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely soph
nvdapple
CVE-2022-42856P1HIGHCVSS 8.8KEVfixed in 16.2≥ unspecified, < 16.2+3 more2022-12-15
CVE-2022-42856 [HIGH] CWE-843 CVE-2022-42856: A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of
nvd
CVE-2023-42917P1HIGHCVSS 8.8KEVv17.22023-12-11
CVE-2023-42917 [HIGH] CVE-2023-42917: tvOS 17.2
Apple Security Update: About the security content of tvOS 17.2
Product: tvOS
Version: 17.2
CVE: CVE-2023-42917
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Description: A memory corruption vulnerability was addressed with improved locking.
apple
1 / 119Next →