Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 30 of 119
CVE-2021-30846P3HIGHCVSS 7.8fixed in 15.0≥ unspecified, < 152021-10-19
CVE-2021-30846 [HIGH] CWE-787 CVE-2021-30846: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2014-4380P3CRITICALCVSS 9.3≤ 6.2v6.0+5 more2014-09-18
CVE-2014-4380 [CRITICAL] CWE-119 CVE-2014-4380: The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds che
The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code in the kernel's context via a crafted application.
nvd
CVE-2016-1727P3HIGHCVSS 8.8fixed in 9.1.12016-02-01
CVE-2016-1727 [HIGH] CVE-2016-1727: WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote
WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1724.
nvdapple
CVE-2021-30984P3HIGHCVSS 7.5fixed in 15.22021-08-24
CVE-2021-30984 [HIGH] CWE-362 CVE-2021-30984: A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2016-4738P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4738 [HIGH] CWE-119 CVE-2016-4738: libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remot
libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2016-9841P3CRITICALCVSS 9.8fixed in 11.02017-05-23
CVE-2016-9841 [CRITICAL] CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by levera
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvdapple
CVE-2022-22632P3CRITICALCVSS 9.8fixed in 15.4≥ unspecified, < 15.42022-03-18
CVE-2022-22632 [CRITICAL] CVE-2022-22632: A logic issue was addressed with improved state management. This issue is fixed in tvOS 15.4, iOS 15
A logic issue was addressed with improved state management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, watchOS 8.5, macOS Monterey 12.3. A malicious application may be able to elevate privileges.
nvdapple
CVE-2024-40815P3HIGHCVSS 7.5fixed in 17.62024-07-29
CVE-2024-40815 [HIGH] CWE-362 CVE-2024-40815: A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadO
A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvdapple
CVE-2022-42845P3HIGHCVSS 7.2fixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-42845 [HIGH] CWE-787 CVE-2022-42845: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monte
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2018-4124P3CRITICALCVSS 9.8fixed in 11.2.62018-04-03
CVE-2018-4124 [CRITICAL] CWE-119 CVE-2018-4124: An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly
nvdapple
CVE-2025-43342P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43342 [CRITICAL] CWE-20 CVE-2025-43342: A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 a
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2016-1783P3HIGHCVSS 8.8fixed in 9.22016-03-24
CVE-2016-1783 [HIGH] CWE-119 CVE-2016-1783: WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to ex
WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2017-15412P3HIGHCVSS 8.8v11.32018-03-29
CVE-2017-15412 [HIGH] CVE-2017-15412: tvOS 11.3
Apple Security Update: About the security content of tvOS 11.3
Product: tvOS
Version: 11.3
CVE: CVE-2017-15412
Component: Kernel
Impact: A malicious application may be able to determine kernel memory layout
Description: An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
apple
CVE-2021-21779P3HIGHCVSS 8.8v14.62021-05-24
CVE-2021-21779 [HIGH] CVE-2021-21779: tvOS 14.6
Apple Security Update: About the security content of tvOS 14.6
Product: tvOS
Version: 14.6
CVE: CVE-2021-21779
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2026-64726P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64726 [CRITICAL] CWE-119 CVE-2026-64726: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
nvd
CVE-2017-13885P3HIGHCVSS 8.8fixed in 11.22018-04-03
CVE-2017-13885 [HIGH] CWE-119 CVE-2017-13885: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of servi
nvdapple
CVE-2017-7160P3HIGHCVSS 8.8fixed in 11.22017-12-27
CVE-2017-7160 [HIGH] CWE-119 CVE-2017-7160: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple
CVE-2017-7068P3HIGHCVSS 8.8≤ 10.2.12017-07-20
CVE-2017-7068 [HIGH] CWE-119 CVE-2017-7068: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvdapple
CVE-2017-7157P3HIGHCVSS 8.8fixed in 11.22017-12-27
CVE-2017-7157 [HIGH] CWE-119 CVE-2017-7157: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple
CVE-2017-7156P3HIGHCVSS 8.8fixed in 11.22017-12-27
CVE-2017-7156 [HIGH] CWE-119 CVE-2017-7156: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service
nvdapple