cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 115 of 119
CVE-2025-30425P4MEDIUMCVSS 4.3fixed in 18.42025-03-31
CVE-2025-30425 [MEDIUM] CWE-284 CVE-2025-30425: This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.
nvdapple
CVE-2023-35984P4MEDIUMCVSS 4.3fixed in 17.0≥ unspecified, < 172023-09-27
CVE-2023-35984 [MEDIUM] CWE-787 CVE-2023-35984: The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An attacker in physical proximity can cause a limited out of bounds write.
nvdapple
CVE-2025-43392P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43392 [MEDIUM] CWE-942 CVE-2025-43392: The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18 The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A website may exfiltrate image data cross-origin.
nvdapple
CVE-2026-39869P4MEDIUMCVSS 4.3fixed in 26.52026-05-11
CVE-2026-39869 [MEDIUM] CWE-120 CVE-2026-39869: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file may terminate the process.
nvd
CVE-2025-46299P4MEDIUMCVSS 4.3fixed in 26.22026-01-09
CVE-2025-46299 [MEDIUM] CWE-284 CVE-2025-46299: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Sa A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
nvdapple
CVE-2014-4373P4MEDIUMCVSS 5.5≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4373 [MEDIUM] CVE-2014-4373: The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV The IntelAccelerator driver in the IOAcceleratorFamily subsystem in Apple iOS before 8 and Apple TV before 7 allows attackers to cause a denial of service (NULL pointer dereference and device restart) via a crafted application.
nvd
CVE-2016-1865P4MEDIUMCVSS 5.5fixed in 9.2.22016-07-22
CVE-2016-1865 [MEDIUM] CWE-476 CVE-2016-1865: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2 The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
nvdapple
CVE-2024-23293P4MEDIUMCVSS 4.6fixed in 17.42024-03-08
CVE-2024-23293 [MEDIUM] CVE-2024-23293: This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.
nvdapple
CVE-2026-28992P4MEDIUMCVSS 4.7fixed in 26.52026-05-11
CVE-2026-28992 [MEDIUM] CWE-362 CVE-2026-28992: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination.
nvd
CVE-2022-22621P4MEDIUMCVSS 4.6fixed in 15.4≥ unspecified, < 15.42022-03-18
CVE-2022-22621 [MEDIUM] CVE-2022-22621: This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvdapple
CVE-2021-30810P4MEDIUMCVSS 4.3fixed in 15.0≥ unspecified, < 152021-10-19
CVE-2021-30810 [MEDIUM] CWE-862 CVE-2021-30810: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 a An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.
nvdapple
CVE-2022-32857P4MEDIUMCVSS 4.3fixed in 15.6≥ unspecified, < 15.62022-08-24
CVE-2022-32857 [MEDIUM] CWE-319 CVE-2022-32857: This issue was addressed by using HTTPS when sending information over the network. This issue is fix This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a user’s activity.
nvdapple
CVE-2025-43374P4MEDIUMCVSS 4.3fixed in 18.52025-11-21
CVE-2025-43374 [MEDIUM] CWE-121 CVE-2025-43374: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory.
nvdapple
CVE-2025-43265P4MEDIUMCVSS 4.0fixed in 18.62025-07-30
CVE-2025-43265 [MEDIUM] CWE-125 CVE-2025-43265: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18 An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.
nvdapple
CVE-2015-8035P4LOWCVSS 2.6≤ 9.12015-11-18
CVE-2015-8035 [LOW] CWE-399 CVE-2015-8035: The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, whic The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
nvdapple
CVE-2016-1814P4MEDIUMCVSS 5.5fixed in 9.2.12016-05-20
CVE-2016-1814 [MEDIUM] CWE-476 CVE-2016-1814: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows att IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
nvdapple
CVE-2017-7003P4MEDIUMCVSS 5.5fixed in 10.2.12018-04-03
CVE-2017-7003 [MEDIUM] CWE-20 CVE-2017-7003: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted file.
nvdapple
CVE-2016-7615P4MEDIUMCVSS 5.5v10.12016-12-12
CVE-2016-7615 [MEDIUM] CVE-2016-7615: tvOS 10.1 Apple Security Update: About the security content of tvOS 10.1 Product: tvOS Version: 10.1 CVE: CVE-2016-7615 Component: Kernel Impact: A local user may be able to cause a system denial of service Description: A denial of service issue was addressed through improved memory handling.
apple
CVE-2026-43743P4MEDIUMCVSS 4.7fixed in 26.62026-06-29
CVE-2026-43743 [MEDIUM] CWE-362 CVE-2026-43743: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and i A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2023-32391P4MEDIUMCVSS 4.6v16.52023-05-18
CVE-2023-32391 [MEDIUM] CVE-2023-32391: tvOS 16.5 Apple Security Update: About the security content of tvOS 16.5 Product: tvOS Version: 16.5 CVE: CVE-2023-32391 Component: Shortcuts Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user Description: The issue was addressed with improved checks.
apple
Apple tvOS vulnerabilities | cvebase