Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 83 of 119
CVE-2025-31215P4MEDIUMCVSS 6.5fixed in 18.52025-05-12
CVE-2025-31215 [MEDIUM] CWE-20 CVE-2025-31215: The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2024-54478P4MEDIUMCVSS 6.5fixed in 18.22025-01-27
CVE-2024-54478 [MEDIUM] CWE-125 CVE-2024-54478: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2024-54467P4MEDIUMCVSS 6.5fixed in 18.0fixed in 182025-03-10
CVE-2024-54467 [MEDIUM] CWE-200 CVE-2024-54467: A cookie management issue was addressed with improved state management. This issue is fixed in Safar
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.
nvdapple
CVE-2026-28863P4MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-28863 [MEDIUM] CWE-284 CVE-2026-28863: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.4 and iPadOS 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to fingerprint the user.
nvd
CVE-2026-28918P4MEDIUMCVSS 6.5fixed in 26.52026-05-11
CVE-2026-28918 [MEDIUM] CWE-125 CVE-2026-28918: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.
nvd
CVE-2026-43703P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43703 [MEDIUM] CWE-125 CVE-2026-43703: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2025-31205P4MEDIUMCVSS 6.5fixed in 18.52025-05-12
CVE-2025-31205 [MEDIUM] CWE-352 CVE-2025-31205: The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadO
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A malicious website may exfiltrate data cross-origin.
nvdapple
CVE-2026-43712P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43712 [MEDIUM] CWE-125 CVE-2026-43712: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2016-7579P4MEDIUMCVSS 5.9fixed in 10.0.12017-02-20
CVE-2016-7579 [MEDIUM] CWE-200 CVE-2016-7579: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "CFNetwork Proxies" component, which allows man-in-the-middle attackers to spoof a proxy password authentication requirement and obtain sensitive information.
nvdapple
CVE-2025-46298P4MEDIUMCVSS 6.5fixed in 26.22026-01-09
CVE-2025-46298 [MEDIUM] CWE-119 CVE-2025-46298: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2026-43734P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43734 [MEDIUM] CWE-416 CVE-2026-43734: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43709P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43709 [MEDIUM] CWE-416 CVE-2026-43709: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43699P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43699 [MEDIUM] CWE-416 CVE-2026-43699: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43726P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43726 [MEDIUM] CWE-416 CVE-2026-43726: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43717P4MEDIUMCVSS 6.5fixed in 26.62026-06-29
CVE-2026-43717 [MEDIUM] CWE-416 CVE-2026-43717: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2016-4679P4MEDIUMCVSS 5.5fixed in 10.0.12017-02-20
CVE-2016-4679 [MEDIUM] CWE-59 CVE-2016-4679: An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libarchive" component, which allows remote attackers to write to arbitrary files via a crafted archive containing a symlink.
nvdapple
CVE-2024-23218P4MEDIUMCVSS 5.9fixed in 17.32024-01-23
CVE-2024-23218 [MEDIUM] CWE-203 CVE-2024-23218: A timing side-channel issue was addressed with improvements to constant-time computation in cryptogr
A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 cipherte
nvdapple
CVE-2024-44176P4MEDIUMCVSS 5.5fixed in 18.0fixed in 182024-09-17
CVE-2024-44176 [MEDIUM] CWE-400 CVE-2024-44176: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. Processing an image may lead to a denial-of-service.
nvdapple
CVE-2024-54494P4MEDIUMCVSS 5.9fixed in 18.22024-12-12
CVE-2024-54494 [MEDIUM] CWE-362 CVE-2024-54494: A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadO
A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An attacker may be able to create a read-only memory mapping that can be written to.
nvd
CVE-2024-40777P4MEDIUMCVSS 5.5fixed in 17.62024-07-29
CVE-2024-40777 [MEDIUM] CWE-787 CVE-2024-40777: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.
nvdapple