Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 82 of 119
CVE-2023-6277P4MEDIUMCVSS 6.5v17.62024-07-29
CVE-2023-6277 [MEDIUM] CVE-2023-6277: tvOS 17.6
Apple Security Update: About the security content of tvOS 17.6
Product: tvOS
Version: 17.6
CVE: CVE-2023-6277
Component: CVE-2023-6277
apple
CVE-2026-43813P4HIGHCVSS 7.1fixed in 26.62026-07-27
CVE-2026-43813 [HIGH] CWE-20 CVE-2026-43813: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.
nvd
CVE-2018-4460P4MEDIUMCVSS 6.5fixed in 12.1.12019-04-03
CVE-2018-4460 [MEDIUM] CWE-20 CVE-2018-4460: A denial of service issue was addressed by removing the vulnerable code. This issue affected version
A denial of service issue was addressed by removing the vulnerable code. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvdapple
CVE-2021-1860P4MEDIUMCVSS 6.5fixed in 14.5≥ unspecified, < 14.52021-09-08
CVE-2021-1860 [MEDIUM] CWE-665 CVE-2021-1860: A memory initialization issue was addressed with improved memory handling. This issue is fixed in Se
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to disclose kernel memory.
nvd
CVE-2022-22592P4MEDIUMCVSS 6.5fixed in 15.3≥ unspecified, < 15.32022-03-18
CVE-2022-22592 [MEDIUM] CVE-2022-22592: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvdapple
CVE-2017-2493P4MEDIUMCVSS 6.5fixed in 10.22018-04-03
CVE-2017-2493 [MEDIUM] CWE-200 CVE-2017-2493: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted elements on a web s
nvdapple
CVE-2019-8517P4MEDIUMCVSS 6.5fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8517 [MEDIUM] CWE-125 CVE-2019-8517: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.2,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvdapple
CVE-2025-24158P4MEDIUMCVSS 6.5fixed in 18.32025-01-27
CVE-2025-24158 [MEDIUM] CWE-79 CVE-2025-24158: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2021-1857P4MEDIUMCVSS 6.5fixed in 14.5≥ unspecified, < 14.52021-09-08
CVE-2021-1857 [MEDIUM] CWE-665 CVE-2021-1857: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iT
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitiv
nvd
CVE-2023-38599P4MEDIUMCVSS 6.5fixed in 16.6≥ unspecified, < 16.62023-07-28
CVE-2023-38599 [MEDIUM] CVE-2023-38599: A logic issue was addressed with improved state management. This issue is fixed in Safari 16.6, watc
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A website may be able to track sensitive user information.
nvdapple
CVE-2022-22589P4MEDIUMCVSS 6.1fixed in 15.3≥ unspecified, < 15.32022-03-18
CVE-2022-22589 [MEDIUM] CVE-2022-22589: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
nvdapple
CVE-2025-24162P4MEDIUMCVSS 6.5fixed in 18.32025-01-27
CVE-2025-24162 [MEDIUM] CWE-125 CVE-2025-24162: This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2023-27954P4MEDIUMCVSS 6.5fixed in 16.4≥ unspecified, < 16.42023-05-08
CVE-2023-27954 [MEDIUM] CWE-863 CVE-2023-27954: The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, S
The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information.
nvdapple
CVE-2017-7153P4MEDIUMCVSS 6.1fixed in 11.22018-04-03
CVE-2017-7153 [MEDIUM] CWE-601 CVE-2017-7153: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof user-interf
nvdapple
CVE-2019-8525P4MEDIUMCVSS 6.7v12.22019-03-25
CVE-2019-8525 [MEDIUM] CVE-2019-8525: tvOS 12.2
Apple Security Update: About the security content of tvOS 12.2
Product: tvOS
Version: 12.2
CVE: CVE-2019-8525
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved state management.
apple
CVE-2024-44297P4MEDIUMCVSS 6.5fixed in 18.12024-10-28
CVE-2024-44297 [MEDIUM] CVE-2024-44297: The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing a maliciously crafted message may lead to a denial-of-service.
nvd
CVE-2022-22594P4MEDIUMCVSS 6.5fixed in 15.3≥ unspecified, < 15.32022-03-18
CVE-2022-22594 [MEDIUM] CWE-346 CVE-2022-22594: A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is
A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.
nvdapple
CVE-2024-27830P4MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27830 [MEDIUM] CVE-2024-27830: This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS
This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. A maliciously crafted webpage may be able to fingerprint the user.
nvdapple
CVE-2025-31217P4MEDIUMCVSS 6.5fixed in 18.52025-05-12
CVE-2025-31217 [MEDIUM] CWE-20 CVE-2025-31217: The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5
The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2024-27800P4MEDIUMCVSS 6.5fixed in 17.52024-06-10
CVE-2024-27800 [MEDIUM] CWE-400 CVE-2024-27800: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPad
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a maliciously crafted message may lead to a denial-of-service.
nvdapple