Apple tvOS vulnerabilities
2,227 known vulnerabilities affecting apple/tvos.
Total CVEs
2,227
CISA KEV
41
actively exploited
Public exploits
199
Exploited in wild
31
Severity breakdown
CRITICAL148HIGH1222MEDIUM795LOW59UNKNOWN3
Vulnerabilities
Page 29 of 112
CVE-2022-46696HIGHCVSS 8.8fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-46696 [HIGH] CWE-787 CVE-2022-46696: A memory corruption issue was addressed with improved input validation. This issue is fixed in Safar
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-42848HIGHCVSS 7.8fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42848 [HIGH] CWE-693 CVE-2022-42848: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, i
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42867HIGHCVSS 8.8fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42867 [HIGH] CWE-416 CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-46691HIGHCVSS 8.8fixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-46691 [HIGH] CWE-787 CVE-2022-46691: A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safar
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2022-42864HIGHCVSS 7.0fixed in 16.2≥ unspecified, < 16.2+3 more2022-12-15
CVE-2022-42864 [HIGH] CWE-362 CVE-2022-42864: A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-46693HIGHCVSS 7.8fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-46693 [HIGH] CWE-787 CVE-2022-46693: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tv
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.
nvd
CVE-2022-46692MEDIUMCVSS 5.5fixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-46692 [MEDIUM] CWE-345 CVE-2022-46692: A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.
nvd
CVE-2022-42866MEDIUMCVSS 5.5fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42866 [MEDIUM] CWE-200 CVE-2022-42866: The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.
nvd
CVE-2022-42851MEDIUMCVSS 5.5fixed in 16.2≥ unspecified, < 16.22022-12-15
CVE-2022-42851 [MEDIUM] CWE-125 CVE-2022-42851: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2. Parsing a maliciously crafted TIFF file may lead to disclosure of user information.
nvd
CVE-2022-46695MEDIUMCVSS 6.5fixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-46695 [MEDIUM] CWE-1021 CVE-2022-46695: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2022-42865MEDIUMCVSS 5.5fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42865 [MEDIUM] CWE-284 CVE-2022-42865: This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
nvd
CVE-2022-42852MEDIUMCVSS 6.5fixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-42852 [MEDIUM] CWE-200 CVE-2022-42852: The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2022-42843MEDIUMCVSS 5.5fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42843 [MEDIUM] CWE-200 CVE-2022-42843: This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 1
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
nvd
CVE-2022-46698MEDIUMCVSS 6.5fixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-46698 [MEDIUM] CWE-693 CVE-2022-46698: A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCl
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2022-40304HIGHCVSS 7.8fixed in 16.22022-11-23
CVE-2022-40304 [HIGH] CWE-415 CVE-2022-40304: An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
nvd
CVE-2022-40303HIGHCVSS 7.5fixed in 16.22022-11-23
CVE-2022-40303 [HIGH] CWE-190 CVE-2022-40303: An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with th
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
nvd
CVE-2022-42808CRITICALCVSS 9.8fixed in 16.1≥ unspecified, < 16.12022-11-01
CVE-2022-42808 [CRITICAL] CWE-787 CVE-2022-42808: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvO
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.
nvdapple
CVE-2022-42813CRITICALCVSS 9.8fixed in 16.1≥ unspecified, < 16.12022-11-01
CVE-2022-42813 [CRITICAL] CWE-295 CVE-2022-42813: A certificate validation issue existed in the handling of WKWebView. This issue was addressed with i
A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.
nvdapple
CVE-2022-32907HIGHCVSS 7.8fixed in 16.02022-11-01
CVE-2022-32907 [HIGH] CWE-269 CVE-2022-32907: This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An
This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2022-26717HIGHCVSS 8.8fixed in 15.52022-11-01
CVE-2022-26717 [HIGH] CWE-416 CVE-2022-26717: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple