Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 36 of 119
CVE-2016-1857P3HIGHCVSS 8.8fixed in 9.2.12016-05-20
CVE-2016-1857 [HIGH] CVE-2016-1857: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.
nvdapple
CVE-2016-4737P3HIGHCVSS 8.8≤ 10.02016-09-25
CVE-2016-4737 [HIGH] CWE-119 CVE-2016-4737: WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote
WebKit in Apple iOS before 10, Safari before 10, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2026-43810P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43810 [CRITICAL] CWE-119 CVE-2026-43810: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43807P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43807 [CRITICAL] CWE-120 CVE-2026-43807: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.
nvd
CVE-2016-4730P3HIGHCVSS 8.8≤ 10.02016-09-25
CVE-2016-4730 [HIGH] CVE-2016-4730: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2016-4735P3HIGHCVSS 8.8fixed in 10.02016-09-25
CVE-2016-4735 [HIGH] CVE-2016-4735: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4734.
nvdapple
CVE-2026-64751P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64751 [CRITICAL] CWE-416 CVE-2026-64751: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2016-4624P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4624 [HIGH] CVE-2016-4624: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4623.
nvdapple
CVE-2016-4623P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4623 [HIGH] CVE-2016-4623: WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4624.
nvdapple
CVE-2016-4589P3HIGHCVSS 8.8v9.2.22016-07-18
CVE-2016-4589 [HIGH] CVE-2016-4589: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4589
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed through improved memory handling.
apple
CVE-2016-1856P3HIGHCVSS 8.8fixed in 9.2.12016-05-20
CVE-2016-1856 [HIGH] CVE-2016-1856: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857.
nvdapple
CVE-2016-1854P3HIGHCVSS 8.8fixed in 9.2.12016-05-20
CVE-2016-1854 [HIGH] CWE-119 CVE-2016-1854: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857.
nvdapple
CVE-2016-7595P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7595 [HIGH] CVE-2016-7595: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-7595
Component: CoreText
Impact: Processing a maliciously crafted font file may lead to arbitrary code execution
Description: Multiple memory corruption issues existed in the handling of font files. These issues were addressed through improved bounds checking.
apple
CVE-2016-7658P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7658 [HIGH] CVE-2016-7658: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-7658
Component: Audio
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-7588P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7588 [HIGH] CVE-2016-7588: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-7588
Component: CoreMedia Playback
Impact: Processing a maliciously crafted .mp4 file may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2016-7659P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-7659 [HIGH] CVE-2016-7659: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-7659
Component: Audio
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved input validation.
apple
CVE-2016-4691P3HIGHCVSS 8.8v10.12016-12-12
CVE-2016-4691 [HIGH] CVE-2016-4691: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-4691
Component: FontParser
Impact: Processing a maliciously crafted font file may lead to arbitrary code execution
Description: Multiple memory corruption issues existed in the handling of font files. These issues were addressed through improved bounds checking.
apple
CVE-2016-4586P3HIGHCVSS 8.8fixed in 9.2.22016-07-22
CVE-2016-4586 [HIGH] CWE-119 CVE-2016-4586: WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitra
WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvdapple
CVE-2018-4150P3HIGHCVSS 7.8fixed in 11.32018-04-03
CVE-2018-4150 [HIGH] CWE-119 CVE-2018-4150: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2018-4360P3HIGHCVSS 8.8fixed in 122019-04-03
CVE-2018-4360 [HIGH] CWE-119 CVE-2018-4360: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple