cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 111 of 119
CVE-2025-43302P4MEDIUMCVSS 5.5fixed in 26.0fixed in 262025-09-15
CVE-2025-43302 [MEDIUM] CWE-787 CVE-2025-43302: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to cause unexpected system termination.
nvdapple
CVE-2022-32823P4MEDIUMCVSS 5.5fixed in 15.6≥ unspecified, < 15.62022-09-23
CVE-2022-32823 [MEDIUM] CWE-665 CVE-2022-32823: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to leak sensitive user information.
nvdapple
CVE-2023-32404P4MEDIUMCVSS 5.5v16.52023-05-18
CVE-2023-32404 [MEDIUM] CVE-2023-32404: tvOS 16.5 Apple Security Update: About the security content of tvOS 16.5 Product: tvOS Version: 16.5 CVE: CVE-2023-32404 Component: Shortcuts Impact: An app may be able to bypass Privacy preferences Description: This issue was addressed with improved entitlements.
apple
CVE-2023-32399P4MEDIUMCVSS 5.5fixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32399 [MEDIUM] CWE-276 CVE-2023-32399: The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to read sensitive location information.
nvdapple
CVE-2023-28178P4MEDIUMCVSS 5.5≥ unspecified, < 16.42023-05-08
CVE-2023-28178 [MEDIUM] CVE-2023-28178: A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, iOS A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. An app may be able to bypass Privacy preferences.
nvdapple
CVE-2024-54560P4MEDIUMCVSS 5.5fixed in 18.0fixed in 182025-03-10
CVE-2024-54560 [MEDIUM] CWE-269 CVE-2024-54560: A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be able to modify other apps without having App Management permission.
nvdapple
CVE-2025-24111P4MEDIUMCVSS 5.5fixed in 18.32025-05-12
CVE-2025-24111 [MEDIUM] CWE-119 CVE-2025-24111: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.
nvdapple
CVE-2023-32438P4MEDIUMCVSS 5.5≥ unspecified, < 16.32023-09-06
CVE-2023-32438 [MEDIUM] CVE-2023-32438: This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in tvOS 16.3, macOS Ventura 13.2, watchOS 9.3, iOS 16.3 and iPadOS 16.3. An app may be able to bypass Privacy preferences.
nvdapple
CVE-2025-31196P4MEDIUMCVSS 5.5fixed in 18.42025-05-12
CVE-2025-31196 [MEDIUM] CWE-125 CVE-2025-31196: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
nvdapple
CVE-2024-44198P4MEDIUMCVSS 5.5fixed in 18.0fixed in 182024-09-17
CVE-2024-44198 [MEDIUM] CWE-190 CVE-2024-44198: An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 a An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-43398P4MEDIUMCVSS 5.5fixed in 26.12025-11-04
CVE-2025-43398 [MEDIUM] CWE-119 CVE-2025-43398: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination.
nvdapple
CVE-2025-31245P4MEDIUMCVSS 5.5fixed in 18.52025-05-12
CVE-2025-31245 [MEDIUM] CWE-400 CVE-2025-31245: The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5. An app may be able to cause unexpected system termination.
nvdapple
CVE-2021-30884P4MEDIUMCVSS 4.7fixed in 15.0≥ unspecified, < 152021-08-24
CVE-2021-30884 [MEDIUM] CVE-2021-30884: The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Visiting a maliciously crafted website may reveal a user's browsing history.
nvdapple
CVE-2015-7116P4MEDIUMCVSS 4.3≤ 9.02016-01-10
CVE-2015-7116 [MEDIUM] CVE-2015-7116: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.
nvdapple
CVE-2015-7115P4MEDIUMCVSS 4.3≤ 9.02016-01-10
CVE-2015-7115 [MEDIUM] CWE-119 CVE-2015-7115: libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.
nvdapple
CVE-2015-7043P4MEDIUMCVSS 4.3≤ 9.02015-12-11
CVE-2015-7043 [MEDIUM] CVE-2015-7043: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7042.
nvdapple
CVE-2015-7041P4MEDIUMCVSS 4.3≤ 9.02015-12-11
CVE-2015-7041 [MEDIUM] CVE-2015-7041: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7042, and CVE-2015-7043.
nvdapple
CVE-2015-7042P4MEDIUMCVSS 4.3≤ 9.02015-12-11
CVE-2015-7042 [MEDIUM] CVE-2015-7042: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7041, and CVE-2015-7043.
nvdapple
CVE-2015-7040P4MEDIUMCVSS 4.3≤ 9.02015-12-11
CVE-2015-7040 [MEDIUM] CVE-2015-7040: The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7041, CVE-2015-7042, and CVE-2015-7043.
nvdapple
CVE-2018-4092P4MEDIUMCVSS 4.7v11.2.52018-01-23
CVE-2018-4092 [MEDIUM] CVE-2018-4092: tvOS 11.2.5 Apple Security Update: About the security content of tvOS 11.2.5 Product: tvOS Version: 11.2.5 CVE: CVE-2018-4092 Component: Kernel Impact: An application may be able to read restricted memory Description: A race condition was addressed with improved locking.
apple
Apple tvOS vulnerabilities | cvebase