Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 117 of 119
CVE-2026-20671P4LOWCVSS 3.1fixed in 26.32026-02-11
CVE-2026-20671 [LOW] CWE-77 CVE-2026-20671: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to intercept network traffic.
nvdapple
CVE-2013-0964P4LOWCVSS 3.6≤ 5.1.1v1.0.0+26 more2013-01-29
CVE-2013-0964 [LOW] CWE-20 CVE-2013-0964: The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and cop
The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a length of less than one page.
nvd
CVE-2016-4665P4LOWCVSS 3.3≤ 10.02017-02-20
CVE-2016-4665 [LOW] CWE-200 CVE-2016-4665: An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 i
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read audio-recording metadata via a crafted app.
nvdapple
CVE-2016-4664P4LOWCVSS 3.3≤ 10.02017-02-20
CVE-2016-4664 [LOW] CWE-200 CVE-2016-4664: An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 i
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata via a crafted app.
nvdapple
CVE-2019-8502P4LOWCVSS 3.3fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8502 [LOW] CWE-20 CVE-2019-8502: An API issue existed in the handling of dictation requests. This issue was addressed with improved v
An API issue existed in the handling of dictation requests. This issue was addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to initiate a Dictation request without user authorization.
nvdapple
CVE-2024-23291P4LOWCVSS 3.3fixed in 17.42024-03-08
CVE-2024-23291 [LOW] CVE-2024-23291: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to accessibility notifications.
nvdapple
CVE-2023-40395P4LOWCVSS 3.3fixed in 17.0≥ unspecified, < 172023-09-27
CVE-2023-40395 [LOW] CVE-2023-40395: The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 a
The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access contacts.
nvdapple
CVE-2023-40427P4LOWCVSS 3.3fixed in 17.0≥ unspecified, < 172023-09-27
CVE-2023-40427 [LOW] CVE-2023-40427: The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6,
The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read sensitive location information.
nvdapple
CVE-2022-32913P4LOWCVSS 3.3fixed in 16.02022-11-01
CVE-2022-32913 [LOW] CWE-200 CVE-2022-32913: The issue was addressed with additional restrictions on the observability of app states. This issue
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. A sandboxed app may be able to determine which app is currently using the camera.
nvdapple
CVE-2025-43294P4LOWCVSS 3.3fixed in 26.12025-09-15
CVE-2025-43294 [LOW] CWE-284 CVE-2025-43294: An issue existed in the handling of environment variables. This issue was addressed with improved va
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26, tvOS 26.1, watchOS 26.1. An app may be able to access sensitive user data.
nvdapple
CVE-2025-43349P4LOWCVSS 2.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43349 [LOW] CWE-787 CVE-2025-43349: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing a maliciously crafted video file may lead to unexpected app termination.
nvdapple
CVE-2016-7657P4LOWCVSS 3.3v10.12016-12-12
CVE-2016-7657 [LOW] CVE-2016-7657: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-7657
Component: IOKit
Impact: An application may be able to read kernel memory
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2020-9933P4LOWCVSS 3.3fixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-16
CVE-2020-9933 [LOW] CVE-2020-9933: An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.6
An authorization issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8. A malicious application may be able to read sensitive location information.
nvdapple
CVE-2019-8698P4LOWCVSS 3.3fixed in 12.4≥ unspecified, < tvOS 12.42019-12-18
CVE-2019-8698 [LOW] CWE-20 CVE-2019-8698: A validation issue existed in the entitlement verification. This issue was addressed with improved v
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites.
nvdapple
CVE-2022-22670P4LOWCVSS 3.3fixed in 15.4≥ unspecified, < 15.42022-03-18
CVE-2022-22670 [LOW] CVE-2022-22670: An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, i
An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.
nvdapple
CVE-2021-31000P4LOWCVSS 3.3fixed in 15.22021-08-24
CVE-2021-31000 [LOW] CWE-276 CVE-2021-31000: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPad
A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1, tvOS 15.2. A malicious application may be able to read sensitive contact information.
nvdapple
CVE-2020-29623P4LOWCVSS 3.3fixed in 14.3≥ unspecified, < 14.32021-04-02
CVE-2020-29623 [LOW] CVE-2020-29623: "Clear History and Website Data" did not clear the history. The issue was addressed with improved da
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.
nvd
CVE-2023-41065P4LOWCVSS 3.3fixed in 17.0≥ unspecified, < 172023-09-27
CVE-2023-41065 [LOW] CVE-2023-41065: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to read sensitive location information.
nvdapple
CVE-2025-46279P4LOWCVSS 3.3fixed in 26.22025-12-17
CVE-2025-46279 [LOW] CWE-200 CVE-2025-46279: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 an
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to identify what other apps a user has installed.
nvdapple
CVE-2024-40795P4LOWCVSS 3.3fixed in 17.62024-07-29
CVE-2024-40795 [LOW] CVE-2024-40795: This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 1
This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to read sensitive location information.
nvdapple