Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 26 of 119
CVE-2020-9947P3HIGHCVSS 8.8fixed in 14.0≥ unspecified, < 14.02020-12-08
CVE-2020-9947 [HIGH] CWE-416 CVE-2020-9947: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2020-9950P3HIGHCVSS 8.8fixed in 14.0≥ unspecified, < 14.02020-12-08
CVE-2020-9950 [HIGH] CWE-416 CVE-2020-9950: A use after free issue was addressed with improved memory management. This issue is fixed in watchOS
A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, tvOS 14.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2021-30802P3HIGHCVSS 8.8fixed in 14.7≥ unspecified, < 14.72021-09-08
CVE-2021-30802 [HIGH] CWE-416 CVE-2021-30802: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-31008P3HIGHCVSS 8.8fixed in 15.12021-08-24
CVE-2021-31008 [HIGH] CWE-843 CVE-2021-31008: A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 15
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 15.1, tvOS 15.1, iOS 15 and iPadOS 15, macOS Monterey 12.0.1, watchOS 8.1. Processing maliciously crafted web content may lead to code execution.
nvdapple
CVE-2025-24252P3HIGHCVSS 8.8fixed in 18.42025-04-29
CVE-2025-24252 [HIGH] CWE-416 CVE-2025-24252: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.
nvdapple
CVE-2015-7110P4MEDIUMCVSS 6.9PoCv9.1
CVE-2015-7110 [MEDIUM] CVE-2015-7110: tvOS 9.1
Apple Security Update: About the security content of tvOS 9.1
Product: tvOS
Version: 9.1
CVE: CVE-2015-7110
Component: CVE-ID
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: Multiple segment validation issues existed in dyld. These were addressed through improved environment sanitization.
apple
CVE-2020-9932P3HIGHCVSS 8.8fixed in 13.0≥ unspecified, < 132020-10-27
CVE-2020-9932 [HIGH] CWE-787 CVE-2020-9932: A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0
A memory corruption issue was addressed with improved validation. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, tvOS 13. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-54505P3HIGHCVSS 8.8fixed in 18.22024-12-12
CVE-2024-54505 [HIGH] CWE-843 CVE-2024-54505: A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2015-8659P3CRITICALCVSS 10.0≤ 9.12016-01-12
CVE-2015-8659 [CRITICAL] CWE-119 CVE-2015-8659: The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unk
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
nvdapple
CVE-2025-31273P3HIGHCVSS 8.8fixed in 18.62025-07-30
CVE-2025-31273 [HIGH] CWE-119 CVE-2025-31273: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2022-22610P3HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.4+1 more2022-09-23
CVE-2022-22610 [HIGH] CWE-787 CVE-2022-22610: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to code execution.
nvdapple
CVE-2014-1358P3CRITICALCVSS 10.0≤ 6.1.1v6.0+3 more2014-07-01
CVE-2014-1358 [CRITICAL] CWE-189 CVE-2014-1358: Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before
Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.
nvd
CVE-2025-43431P3HIGHCVSS 8.8fixed in 26.12025-11-04
CVE-2025-43431 [HIGH] CWE-787 CVE-2025-43431: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2024-54543P3HIGHCVSS 8.8fixed in 18.22025-01-27
CVE-2024-54543 [HIGH] CWE-787 CVE-2024-54543: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-28955P3HIGHCVSS 8.8fixed in 26.52026-05-11
CVE-2026-28955 [HIGH] CWE-119 CVE-2026-28955: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2014-4487P3CRITICALCVSS 10.0≤ 7.0.12015-01-30
CVE-2014-4487 [CRITICAL] CWE-119 CVE-2014-4487: Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV be
Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvd
CVE-2017-7154P4MEDIUMCVSS 6.6PoCfixed in 11.22017-12-27
CVE-2017-7154 [MEDIUM] CWE-20 CVE-2017-7154: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash).
nvdapple
CVE-2017-7062P3CRITICALCVSS 9.8≤ 10.2.12017-07-20
CVE-2017-7062 [CRITICAL] CWE-119 CVE-2017-7062: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "Contacts" component. A buffer overflow allows remote attackers to execute arbitrary code or cause a denial of service (application crash).
nvdapple
CVE-2026-28847P3HIGHCVSS 8.8fixed in 26.52026-05-11
CVE-2026-28847 [HIGH] CWE-119 CVE-2026-28847: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43705P3HIGHCVSS 8.8fixed in 26.62026-06-29
CVE-2026-43705 [HIGH] CWE-843 CVE-2026-43705: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd