Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 87 of 119
CVE-2013-5198P4MEDIUMCVSS 6.8≤ 6.0.22013-12-18
CVE-2013-5198 [MEDIUM] CWE-119 CVE-2013-5198: WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.
nvd
CVE-2013-5228P4MEDIUMCVSS 6.8≤ 6.0.22013-12-18
CVE-2013-5228 [MEDIUM] CWE-119 CVE-2013-5228: WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.
nvd
CVE-2013-5196P4MEDIUMCVSS 6.8≤ 6.0.22013-12-18
CVE-2013-5196 [MEDIUM] CWE-119 CVE-2013-5196: WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.
nvd
CVE-2013-5197P4MEDIUMCVSS 6.8≤ 6.0.22013-12-18
CVE-2013-5197 [MEDIUM] CWE-119 CVE-2013-5197: WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.
nvd
CVE-2013-5225P4MEDIUMCVSS 6.8≤ 6.0.22013-12-18
CVE-2013-5225 [MEDIUM] CWE-119 CVE-2013-5225: WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execut
WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.
nvd
CVE-2015-7499P4MEDIUMCVSS 5.0≤ 9.12015-12-15
CVE-2015-7499 [MEDIUM] CWE-119 CVE-2015-7499: Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows contex
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
nvdapple
CVE-2021-30788P4HIGHCVSS 7.1fixed in 14.72021-09-08
CVE-2021-30788 [HIGH] CVE-2021-30788: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5,
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
nvd
CVE-2015-1819P4MEDIUMCVSS 5.0≤ 9.12015-08-14
CVE-2015-1819 [MEDIUM] CWE-399 CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) vi
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
nvdapple
CVE-2017-7830P4MEDIUMCVSS 6.5v11.2.52018-01-23
CVE-2017-7830 [MEDIUM] CVE-2017-7830: tvOS 11.2.5
Apple Security Update: About the security content of tvOS 11.2.5
Product: tvOS
Version: 11.2.5
CVE: CVE-2017-7830
Component: WebKit Page Loading
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved memory handling.
apple
CVE-2020-9842P4HIGHCVSS 7.1fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9842 [HIGH] CVE-2020-9842: An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 an
An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application could interact with system processes to access private information and perform privileged actions.
nvd
CVE-2020-9808P4HIGHCVSS 7.1fixed in 13.4.5≥ unspecified, < tvOS 13.4.52020-06-09
CVE-2020-9808 [HIGH] CWE-787 CVE-2020-9808: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2020-13630P4HIGHCVSS 7.0fixed in 14.02020-05-27
CVE-2020-13630 [HIGH] CWE-416 CVE-2020-13630: ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snip
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
nvdapple
CVE-2016-1858P4MEDIUMCVSS 6.5fixed in 9.2.12016-05-20
CVE-2016-1858 [MEDIUM] CWE-200 CVE-2016-1858: WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tr
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
nvdapple
CVE-2016-4587P4MEDIUMCVSS 6.5v9.2.22016-07-18
CVE-2016-4587 [MEDIUM] CVE-2016-4587: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4587
Component: WebKit
Impact: Processing maliciously crafted web content may result in the disclosure of process memory
Description: A memory initialization issue was addressed through improved memory handling.
apple
CVE-2017-7038P4MEDIUMCVSS 6.1fixed in 10.2.22017-07-20
CVE-2017-7038 [MEDIUM] CWE-79 CVE-2017-7038: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvdapple
CVE-2026-20687P4HIGHCVSS 7.1fixed in 26.42026-03-25
CVE-2026-20687 [HIGH] CWE-416 CVE-2026-20687: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2024-44252P4HIGHCVSS 7.1fixed in 18.12024-10-28
CVE-2024-44252 [HIGH] CVE-2024-44252: A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadO
A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2025-43224P4HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43224 [HIGH] CWE-787 CVE-2025-43224: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2025-43221P4HIGHCVSS 7.1fixed in 18.62025-07-30
CVE-2025-43221 [HIGH] CWE-125 CVE-2025-43221: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iO
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2018-4409P4MEDIUMCVSS 6.5fixed in 12.12019-04-03
CVE-2018-4409 [MEDIUM] CWE-400 CVE-2018-4409: A resource exhaustion issue was addressed with improved input validation. This issue affected versio
A resource exhaustion issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple