Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 63 of 119
CVE-2026-43780P3HIGHCVSS 7.8fixed in 26.62026-07-27
CVE-2026-43780 [HIGH] CWE-190 CVE-2026-43780: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 an
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected app termination.
nvd
CVE-2025-24126P3HIGHCVSS 7.3fixed in 18.32025-01-27
CVE-2025-24126 [HIGH] CWE-400 CVE-2025-24126: An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequ
An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to corrupt process memory.
nvdapple
CVE-2022-32830P3HIGHCVSS 7.5fixed in 15.6≥ unspecified, < 15.62023-02-27
CVE-2022-32830 [HIGH] CWE-125 CVE-2022-32830: An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in tvOS
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.6, iOS 15.6 and iPadOS 15.6. Processing a maliciously crafted image may lead to disclosure of user information.
nvdapple
CVE-2025-43462P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43462 [HIGH] CWE-400 CVE-2025-43462: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2026-28987P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28987 [HIGH] CWE-532 CVE-2026-28987: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iP
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state.
nvd
CVE-2026-28974P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28974 [HIGH] CWE-284 CVE-2026-28974: This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
nvd
CVE-2026-43655P3HIGHCVSS 7.3fixed in 26.52026-05-11
CVE-2026-43655 [HIGH] CWE-125 CVE-2026-43655: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2024-9681P3MEDIUMCVSS 6.5v18.42025-03-31
CVE-2024-9681 [MEDIUM] CVE-2024-9681: tvOS 18.4
Apple Security Update: About the security content of tvOS 18.4
Product: tvOS
Version: 18.4
CVE: CVE-2024-9681
Component: CVE-2024-9681
apple
CVE-2026-28972P3MEDIUMCVSS 6.5fixed in 26.52026-05-11
CVE-2026-28972 [MEDIUM] CWE-787 CVE-2026-28972: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2017-9049P3HIGHCVSS 7.5v112017-09-19
CVE-2017-9049 [HIGH] CVE-2017-9049: tvOS 11
Apple Security Update: About the security content of tvOS 11
Product: tvOS
Version: 11
CVE: CVE-2017-9049
Component: CVE-2017-9233
Impact: Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2019-6230P3HIGHCVSS 8.6fixed in 12.1.2≥ unspecified, < tvOS 12.1.22019-03-05
CVE-2019-6230 [HIGH] CWE-665 CVE-2019-6230: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2021-30955P3HIGHCVSS 7.0fixed in 15.22021-08-24
CVE-2021-30955 [HIGH] CWE-362 CVE-2021-30955: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2016-4632P3HIGHCVSS 7.5fixed in 9.2.22016-07-22
CVE-2016-4632 [HIGH] CWE-119 CVE-2016-4632: ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2
ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvdapple
CVE-2016-1818P3HIGHCVSS 7.8≤ 9.22016-05-20
CVE-2016-1818 [HIGH] CVE-2016-1818: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b
IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016-1819.
nvdapple
CVE-2016-4733P3HIGHCVSS 7.8fixed in 10.02016-09-25
CVE-2016-4733 [HIGH] CVE-2016-4733: WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execu
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4734, and CVE-2016-4735.
nvdapple
CVE-2016-4650P3HIGHCVSS 7.8fixed in 9.2.12017-04-20
CVE-2016-4650 [HIGH] CWE-119 CVE-2016-4650: Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS b
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2018-4343P3HIGHCVSS 7.8fixed in 122019-04-03
CVE-2018-4343 [HIGH] CWE-119 CVE-2018-4343: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvdapple
CVE-2018-4126P3HIGHCVSS 7.8fixed in 122019-04-03
CVE-2018-4126 [HIGH] CWE-119 CVE-2018-4126: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvdapple
CVE-2017-2406P3HIGHCVSS 7.8≤ 10.1.12017-04-02
CVE-2017-2406 [HIGH] CWE-119 CVE-2017-2406: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvdapple
CVE-2017-2407P3HIGHCVSS 7.8≤ 10.1.12017-04-02
CVE-2017-2407 [HIGH] CWE-119 CVE-2017-2407: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvdapple