Apple tvOS 18.1 vulnerabilities
2,371 known vulnerabilities affecting apple/tvos at version 18.1.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL149HIGH1258MEDIUM837LOW59UNKNOWN68
Vulnerabilities
Page 4 of 20
CVE-2026-64769P4UNKNOWNfixed in 26.62026-07-27
CVE-2026-64769 CVE-2026-64769: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.
nvd
CVE-2026-43807P4UNKNOWNfixed in 26.62026-07-27
CVE-2026-43807 CVE-2026-43807: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.
nvd
CVE-2026-43812P4UNKNOWNfixed in 26.62026-07-27
CVE-2026-43812 CVE-2026-43812: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64735P4UNKNOWNfixed in 26.62026-07-27
CVE-2026-64735 CVE-2026-64735: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters.
nvd
CVE-2026-64741P4UNKNOWNfixed in 26.62026-07-27
CVE-2026-64741 CVE-2026-64741: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
nvd
CVE-2026-64726P4UNKNOWNfixed in 26.62026-07-27
CVE-2026-64726 CVE-2026-64726: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
nvd
CVE-2026-39868P3CRITICALCVSS 9.1fixed in 26.62026-06-29
CVE-2026-39868 [CRITICAL] CWE-20 CVE-2026-39868: This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadO
This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-43725P3HIGHCVSS 7.1fixed in 26.62026-06-29
CVE-2026-43725 [HIGH] CWE-20 CVE-2026-43725: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2026-43705P3HIGHCVSS 8.8fixed in 26.62026-06-29
CVE-2026-43705 [HIGH] CWE-843 CVE-2026-43705: A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-43724P3HIGHCVSS 7.8fixed in 26.62026-06-29
CVE-2026-43724 [HIGH] CWE-20 CVE-2026-43724: The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPad
The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2026-43701P4HIGHCVSS 7.1fixed in 26.62026-06-29
CVE-2026-43701 [HIGH] CWE-284 CVE-2026-43701: The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and i
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
nvd
CVE-2026-43715P3HIGHCVSS 8.8fixed in 26.62026-06-29
CVE-2026-43715 [HIGH] CWE-416 CVE-2026-43715: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-43735P3HIGHCVSS 8.1fixed in 26.62026-06-29
CVE-2026-43735 [HIGH] CWE-352 CVE-2026-43735: The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and i
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2026-43731P3HIGHCVSS 8.8fixed in 26.62026-06-29
CVE-2026-43731 [HIGH] CWE-416 CVE-2026-43731: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2026-43721P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43721 [MEDIUM] CWE-732 CVE-2026-43721: This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iO
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.
nvd
CVE-2026-43706P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43706 [MEDIUM] CWE-415 CVE-2026-43706: A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43720P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43720 [MEDIUM] CWE-416 CVE-2026-43720: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2026-43734P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43734 [MEDIUM] CWE-416 CVE-2026-43734: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43708P4MEDIUMCVSS 4.3fixed in 26.62026-06-29
CVE-2026-43708 [MEDIUM] CWE-20 CVE-2026-43708: The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.
nvd
CVE-2026-43732P3MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43732 [MEDIUM] CWE-22 CVE-2026-43732: A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2,
A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
nvd