cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 52 of 119
CVE-2019-8562P3CRITICALCVSS 9.6fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8562 [CRITICAL] CWE-787 CVE-2019-8562: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, t A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2026-43661P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-43661 [HIGH] CWE-121 CVE-2026-43661: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.
nvd
CVE-2026-28959P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28959 [HIGH] CWE-120 CVE-2026-28959: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
nvd
CVE-2026-28969P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28969 [HIGH] CWE-416 CVE-2026-28969: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.
nvd
CVE-2026-28860P3HIGHCVSS 7.5fixed in 26.42026-05-11
CVE-2026-28860 [HIGH] CWE-20 CVE-2026-28860: The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A local attacker may be able to modify the state of the Keychain.
nvd
CVE-2026-43654P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-43654 [HIGH] CWE-497 CVE-2026-43654: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to disclose kernel memory.
nvd
CVE-2026-28990P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28990 [HIGH] CWE-119 CVE-2026-28990: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.
nvd
CVE-2018-4210P3HIGHCVSS 8.8fixed in 11.32019-01-11
CVE-2018-4210 [HIGH] CWE-129 CVE-2018-4210: In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 f In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.
nvdapple
CVE-2016-1775P3HIGHCVSS 7.8fixed in 9.22016-03-24
CVE-2016-1775 [HIGH] CWE-119 CVE-2016-1775: TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 TrueTypeScaler in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.
nvdapple
CVE-2016-1740P3HIGHCVSS 7.8fixed in 9.22016-03-24
CVE-2016-1740 [HIGH] CWE-119 CVE-2016-1740: FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all FontParser in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.
nvdapple
CVE-2017-9050P3HIGHCVSS 7.5v112017-09-19
CVE-2017-9050 [HIGH] CVE-2017-9050: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-9050 Component: CVE-2017-9233 Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution Description: A use after free issue was addressed with improved memory management.
apple
CVE-2020-3883P3HIGHCVSS 8.8fixed in 13.4≥ unspecified, < tvOS 13.42020-04-01
CVE-2020-3883 [HIGH] CVE-2020-3883: This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macO This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to use arbitrary entitlements.
nvd
CVE-2022-22637P3HIGHCVSS 8.8fixed in 15.4≥ unspecified, < 15.4+1 more2022-09-23
CVE-2022-22637 [HIGH] CWE-346 CVE-2022-22637: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.
nvdapple
CVE-2018-4269P3HIGHCVSS 8.6fixed in 11.4.12019-04-03
CVE-2018-4269 [HIGH] CWE-119 CVE-2018-4269: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2019-2102P3HIGHCVSS 8.8v12.32019-05-13
CVE-2019-2102 [HIGH] CVE-2019-2102: tvOS 12.3 Apple Security Update: About the security content of tvOS 12.3 Product: tvOS Version: 12.3 CVE: CVE-2019-2102 Component: Bluetooth Impact: Due to a misconfiguration in the Bluetooth pairing protocols of a Bluetooth Low Energy (BLE) version of FIDO Security Keys it may be possible for an attacker with physical proximity to be able to intercept Bluetooth traffic during pairing Description: This issue was addressed by disabling accessories with insecure
apple
CVE-2017-2441P3HIGHCVSS 7.8≤ 10.1.12017-04-02
CVE-2017-2441 [HIGH] CWE-416 CVE-2017-2441: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "libc++abi" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code via a crafted C++ app that is mishandled during dema
nvdapple
CVE-2017-7172P3HIGHCVSS 7.8fixed in 11.22018-04-03
CVE-2017-7172 [HIGH] CWE-119 CVE-2017-7172: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CFNetwork Session" component. It allows attackers to execute arbitra
nvdapple
CVE-2020-9967P3HIGHCVSS 7.8fixed in 14.0≥ unspecified, < 14.02021-04-02
CVE-2020-9967 [HIGH] CWE-787 CVE-2020-9967: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memo
nvdapple
CVE-2023-42947P3HIGHCVSS 8.6fixed in 17.2≥ unspecified, < 17.22024-03-28
CVE-2023-42947 [HIGH] CWE-22 CVE-2023-42947: A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.
nvdapple
CVE-2015-7038P3MEDIUMCVSS 6.8≤ 9.02015-12-11
CVE-2015-7038 [MEDIUM] CWE-119 CVE-2015-7038: Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS b Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7039.
nvdapple
Apple tvOS vulnerabilities | cvebase