cbcvebase.

Apple tvOS vulnerabilities

2,371 known vulnerabilities affecting apple/tvos.

Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3

Vulnerabilities

Page 69 of 119
CVE-2021-1787P3HIGHCVSS 7.8fixed in 14.42021-04-02
CVE-2021-1787 [HIGH] CWE-269 CVE-2021-1787: Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Secur Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges.
nvd
CVE-2022-42849P3HIGHCVSS 7.8fixed in 16.2≥ unspecified, < 16.22022-12-15
CVE-2022-42849 [HIGH] CWE-269 CVE-2022-42849: An access issue existed with privileged API calls. This issue was addressed with additional restrict An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
nvd
CVE-2022-32826P3HIGHCVSS 7.8fixed in 15.6≥ unspecified, < 15.62022-09-23
CVE-2022-32826 [HIGH] CWE-269 CVE-2022-32826: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.
nvdapple
CVE-2025-31219P3HIGHCVSS 7.1fixed in 18.52025-05-12
CVE-2025-31219 [HIGH] CWE-119 CVE-2025-31219: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2016-5131P3HIGHCVSS 8.8fixed in 10.02016-07-23
CVE-2016-5131 [HIGH] CWE-416 CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
nvdapple
CVE-2024-54486P3MEDIUMCVSS 6.5fixed in 18.22024-12-12
CVE-2024-54486 [MEDIUM] CVE-2024-54486: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2019-15163P3HIGHCVSS 7.5v13.32019-12-10
CVE-2019-15163 [HIGH] CVE-2019-15163: tvOS 13.3 Apple Security Update: About the security content of tvOS 13.3 Product: tvOS Version: 13.3 CVE: CVE-2019-15163 Component: CVE-2019-15163
apple
CVE-2022-32816P3MEDIUMCVSS 6.5fixed in 15.6≥ unspecified, < 15.62022-09-23
CVE-2022-32816 [MEDIUM] CWE-451 CVE-2022-32816: The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iO The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2025-30432P3MEDIUMCVSS 6.4fixed in 18.42025-03-31
CVE-2025-30432 [MEDIUM] CWE-287 CVE-2025-30432: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.
nvdapple
CVE-2025-31209P3MEDIUMCVSS 6.3fixed in 18.52025-05-12
CVE-2025-31209 [MEDIUM] CWE-125 CVE-2025-31209: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to disclosure of user information.
nvdapple
CVE-2010-2808P3MEDIUMCVSS 6.8fixed in 4.1.02010-08-19
CVE-2010-2808 [MEDIUM] CWE-120 CVE-2010-2808: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 all Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
nvd
CVE-2017-13813P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13813 [HIGH] CVE-2017-13813: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13813 Component: Kernel Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device. Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addressed by reducing the information available to thi
apple
CVE-2017-13816P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13816 [HIGH] CVE-2017-13816: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13816 Component: Kernel Impact: A malicious application may be able to learn information about the presence and operation of other applications on the device. Description: An application was able to access network activity information maintained by the operating system unrestricted. This issue was addressed by reducing the information available to thi
apple
CVE-2016-1808P3HIGHCVSS 7.8fixed in 9.2.12016-05-20
CVE-2016-1808 [HIGH] CWE-119 CVE-2016-1808: The Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and wat The Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2016-4777P3HIGHCVSS 7.8fixed in 10.02016-09-25
CVE-2016-4777 [HIGH] CWE-264 CVE-2016-4777: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (invalid pointer dereference) via a crafted app.
nvdapple
CVE-2021-30924P3HIGHCVSS 7.5fixed in 15.12021-08-24
CVE-2021-30924 [HIGH] CVE-2021-30924: A denial of service issue was addressed with improved state handling. This issue is fixed in macOS M A denial of service issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.0.1. A remote attacker can cause a device to unexpectedly restart.
nvdapple
CVE-2016-4772P3HIGHCVSS 7.5fixed in 10.02016-09-25
CVE-2016-4772 [HIGH] CWE-399 CVE-2016-4772: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows re The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to cause a denial of service (unintended lock) via unspecified vectors.
nvdapple
CVE-2017-13825P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13825 [HIGH] CVE-2017-13825: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13825 Component: CoreText Impact: Processing a maliciously crafted font file may lead to arbitrary code execution Description: A memory consumption issue was addressed with improved memory handling.
apple
CVE-2016-1754P3HIGHCVSS 7.8fixed in 9.22016-03-24
CVE-2016-1754 [HIGH] CWE-119 CVE-2016-1754: The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1755.
nvdapple
CVE-2017-13833P3HIGHCVSS 7.8v112017-09-19
CVE-2017-13833 [HIGH] CVE-2017-13833: tvOS 11 Apple Security Update: About the security content of tvOS 11 Product: tvOS Version: 11 CVE: CVE-2017-13833 Component: CFNetwork Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling.
apple
Apple tvOS vulnerabilities | cvebase