cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 27 of 119
CVE-2026-28947P3HIGHCVSS 8.8fixed in 26.52026-05-11
CVE-2026-28947 [HIGH] CWE-416 CVE-2026-28947: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2025-43419P3HIGHCVSS 8.8fixed in 26.0fixed in 262025-11-04
CVE-2025-43419 [HIGH] CWE-119 CVE-2025-43419: The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to memory corruption.
nvdapple
CVE-2026-43731P3HIGHCVSS 8.8fixed in 26.62026-06-29
CVE-2026-43731 [HIGH] CWE-416 CVE-2026-43731: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2020-9918P3CRITICALCVSS 9.8fixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-16
CVE-2020-9918 [CRITICAL] CWE-125 CVE-2020-9918: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Cat An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2016-4631P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4631 [HIGH] CWE-119 CVE-2016-4631: ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF file.
nvdapple
CVE-2014-4381P3CRITICALCVSS 9.3≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4381 [CRITICAL] CWE-119 CVE-2014-4381: Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operatio Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.
nvd
CVE-2016-4637P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4637 [HIGH] CWE-119 CVE-2016-4637: CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2 CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted BMP image.
nvdapple
CVE-2025-24211P3CRITICALCVSS 9.8fixed in 18.42025-03-31
CVE-2025-24211 [CRITICAL] CWE-400 CVE-2025-24211: This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 1 This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2015-7055P3CRITICALCVSS 9.3≤ 9.02015-12-11
CVE-2015-7055 [CRITICAL] CWE-284 CVE-2015-7055: AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to acc AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2018-4190P3HIGHCVSS 8.8fixed in 11.42018-06-08
CVE-2018-4190 [HIGH] CWE-522 CVE-2018-4190: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive credential information that is tra
nvdapple
CVE-2020-9883P3HIGHCVSS 7.8fixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-22
CVE-2020-9883 [HIGH] CWE-120 CVE-2020-9883: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.
nvdapple
CVE-2022-32847P3CRITICALCVSS 9.1fixed in 15.6≥ unspecified, < 15.62022-09-23
CVE-2022-32847 [CRITICAL] CWE-119 CVE-2022-32847: This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macO This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2025-43209P3CRITICALCVSS 9.8fixed in 18.62025-07-30
CVE-2025-43209 [CRITICAL] CWE-787 CVE-2025-43209: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43347P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43347 [CRITICAL] CWE-20 CVE-2025-43347: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 2 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An input validation issue was addressed.
nvdapple
CVE-2013-0340P3MEDIUMCVSS 6.8fixed in 15.02014-01-21
CVE-2013-0340 [MEDIUM] CWE-611 CVE-2013-0340: expat before version 2.4.0 does not properly handle entities expansion unless an application develop expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE
nvdapple
CVE-2017-2485P3HIGHCVSS 8.8≤ 10.1.12017-04-02
CVE-2017-2485 [HIGH] CWE-416 CVE-2017-2485: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Security" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvdapple
CVE-2016-4688P3HIGHCVSS 8.8fixed in 10.0.12017-02-20
CVE-2016-4688 [HIGH] CWE-119 CVE-2016-4688: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overfl
nvdapple
CVE-2026-64770P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64770 [CRITICAL] CWE-787 CVE-2026-64770: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
CVE-2026-64774P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64774 [CRITICAL] CWE-190 CVE-2026-64774: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 an An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
CVE-2026-64769P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64769 [CRITICAL] CWE-787 CVE-2026-64769: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
Apple tvOS vulnerabilities | cvebase