Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68
Vulnerabilities
Page 4 of 119
CVE-2022-46690P1HIGHCVSS 7.8Exploitedfixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-46690 [HIGH] CWE-787 CVE-2022-46690: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-42855P1HIGHCVSS 7.1Exploitedfixed in 16.2≥ unspecified, < 16.2+3 more2022-12-15
CVE-2022-42855 [HIGH] CWE-269 CVE-2022-42855: A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.
nvd
CVE-2020-9870P1HIGHCVSS 8.8Exploitedfixed in 13.4.8≥ unspecified, < tvOS 13.4.82020-10-16
CVE-2020-9870 [HIGH] CWE-20 CVE-2020-9870: A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.
A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attacker with memory write capability may be able to bypass pointer authentication codes and run arbitrary code.
nvd
CVE-2022-46695P1MEDIUMCVSS 6.5Exploitedfixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-46695 [MEDIUM] CWE-1021 CVE-2022-46695: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.
nvd
CVE-2021-30737P1HIGHCVSS 8.8Exploitedfixed in 14.62021-09-08
CVE-2021-30737 [HIGH] CWE-787 CVE-2021-30737: A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This i
A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, iOS 12.5.4, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted certificate may lead to arbitrary code execution.
nvdapple
CVE-2022-46694P1HIGHCVSS 7.8Exploitedfixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-46694 [HIGH] CWE-787 CVE-2022-46694: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.
nvd
CVE-2022-40303P2HIGHCVSS 7.5Exploitedfixed in 16.22022-11-23
CVE-2022-40303 [HIGH] CWE-190 CVE-2022-40303: An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with th
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
nvd
CVE-2022-42852P1MEDIUMCVSS 6.5Exploitedfixed in 16.2≥ unspecified, < 16.2+2 more2022-12-15
CVE-2022-42852 [MEDIUM] CWE-200 CVE-2022-42852: The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
nvd
CVE-2022-40304P2HIGHCVSS 7.8Exploitedfixed in 16.22022-11-23
CVE-2022-40304 [HIGH] CWE-415 CVE-2022-40304: An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
nvd
CVE-2021-1801P1MEDIUMCVSS 6.5Exploitedfixed in 14.42021-04-02
CVE-2021-1801 [MEDIUM] CVE-2021-1801: This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Maliciously crafted web content may violate iframe sandboxing policy.
nvd
CVE-2023-32402P1MEDIUMCVSS 6.5Exploitedfixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32402 [MEDIUM] CWE-125 CVE-2023-32402: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
nvdapple
CVE-2022-42848P2HIGHCVSS 7.8Exploitedfixed in 16.2≥ unspecified, < 16.2+1 more2022-12-15
CVE-2022-42848 [HIGH] CWE-693 CVE-2022-42848: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, i
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2022-46705P1MEDIUMCVSS 4.3Exploitedfixed in 16.22023-02-27
CVE-2022-46705 [MEDIUM] CVE-2022-46705: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2023-32423P2MEDIUMCVSS 6.5Exploitedfixed in 16.5≥ unspecified, < 16.52023-06-23
CVE-2023-32423 [MEDIUM] CWE-120 CVE-2023-32423: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
nvdapple
CVE-2021-30895P2MEDIUMCVSS 5.5Exploitedfixed in 15.12021-08-24
CVE-2021-30895 [MEDIUM] CVE-2021-30895: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, tvOS 15.1, watchOS 8.1, macOS Monterey 12.0.1. A malicious application may be able to access information about a user's contacts.
nvdapple
CVE-2021-30896P2MEDIUMCVSS 5.5Exploitedfixed in 15.12021-08-24
CVE-2021-30896 [MEDIUM] CVE-2021-30896: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, tvOS 15.1, watchOS 8.1, macOS Monterey 12.0.1. A malicious application may be able to read user's gameplay data.
nvdapple
CVE-2023-23524P2HIGHCVSS 7.5Exploitedfixed in 16.3.2≥ unspecified, < 16.32023-02-27
CVE-2023-23524 [HIGH] CWE-400 CVE-2023-23524: A denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS
A denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, watchOS 9.3.1, macOS Ventura 13.2.1. Processing a maliciously crafted certificate may lead to a denial-of-service.
nvdapple
CVE-2020-9850P1CRITICALCVSS 9.8PoCfixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9850 [CRITICAL] CVE-2020-9850: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code execution.
nvd
CVE-2025-43532P2LOWCVSS 2.8Exploitedfixed in 26.22025-12-12
CVE-2025-43532 [LOW] CWE-120 CVE-2025-43532: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malicious data may lead to unexpected app termination.
nvdapple
CVE-2017-9417P1CRITICALCVSS 9.8PoCv10.2.22017-07-19
CVE-2017-9417 [CRITICAL] CVE-2017-9417: tvOS 10.2.2
Apple Security Update: About the security content of tvOS 10.2.2
Product: tvOS
Version: 10.2.2
CVE: CVE-2017-9417
Component: Wi-Fi
Impact: An attacker within range may be able to execute arbitrary code on the Wi-Fi chip
Description: A memory corruption issue was addressed with improved memory handling.
apple