Apple tvOS vulnerabilities
2,371 known vulnerabilities affecting apple/tvos.
Total CVEs
2,371
CISA KEV
41
actively exploited
Public exploits
209
Exploited in wild
78
Severity breakdown
CRITICAL174HIGH1277MEDIUM858LOW59UNKNOWN3
Vulnerabilities
Page 94 of 119
CVE-2025-24097P4MEDIUMCVSS 5.0fixed in 18.42025-03-31
CVE-2025-24097 [MEDIUM] CWE-125 CVE-2025-24097: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to read arbitrary file metadata.
nvdapple
CVE-2015-7500P4MEDIUMCVSS 5.0≤ 9.12015-12-15
CVE-2015-7500 [MEDIUM] CWE-119 CVE-2015-7500: The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
nvdapple
CVE-2016-7627P4MEDIUMCVSS 6.5v10.12016-12-12
CVE-2016-7627 [MEDIUM] CVE-2016-7627: tvOS 10.1
Apple Security Update: About the security content of tvOS 10.1
Product: tvOS
Version: 10.1
CVE: CVE-2016-7627
Component: CoreGraphics
Impact: Processing a maliciously crafted font file may lead to unexpected application termination
Description: A null pointer dereference was addressed through improved input validation.
apple
CVE-2016-4585P4MEDIUMCVSS 6.1v9.2.22016-07-18
CVE-2016-4585 [MEDIUM] CVE-2016-4585: tvOS 9.2.2
Apple Security Update: About the security content of tvOS 9.2.2
Product: tvOS
Version: 9.2.2
CVE: CVE-2016-4585
Component: WebKit Page Loading
Impact: A malicious website may exfiltrate data cross-origin
Description: A cross-site scripting issue existed in Safari URL redirection. This issue was addressed through improved URL validation on redirection.
apple
CVE-2018-4305P4MEDIUMCVSS 6.5fixed in 122019-04-03
CVE-2018-4305 [MEDIUM] CWE-20 CVE-2018-4305: An input validation issue was addressed with improved input validation. This issue affected versions
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvdapple
CVE-2021-30866P4MEDIUMCVSS 6.5fixed in 15.0≥ unspecified, < 152021-08-24
CVE-2021-30866 [MEDIUM] CVE-2021-30866: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvO
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A device may be passively tracked by its WiFi MAC address.
nvdapple
CVE-2025-24251P4MEDIUMCVSS 6.5fixed in 18.42025-04-29
CVE-2025-24251 [MEDIUM] CWE-476 CVE-2025-24251: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may cause an unexpected app termination.
nvdapple
CVE-2025-30445P4MEDIUMCVSS 6.5fixed in 18.42025-04-29
CVE-2025-30445 [MEDIUM] CWE-843 CVE-2025-30445: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadO
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.
nvdapple
CVE-2025-31203P4MEDIUMCVSS 6.5fixed in 18.42025-04-29
CVE-2025-31203 [MEDIUM] CWE-190 CVE-2025-31203: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 an
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may be able to cause a denial-of-service.
nvdapple
CVE-2019-8764P4MEDIUMCVSS 6.1v132019-09-24
CVE-2019-8764 [MEDIUM] CVE-2019-8764: tvOS 13
Apple Security Update: About the security content of tvOS 13
Product: tvOS
Version: 13
CVE: CVE-2019-8764
Component: WebKit
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue was addressed with improved state management.
apple
CVE-2017-7109P4MEDIUMCVSS 6.1≤ 10.2.22017-10-23
CVE-2017-7109 [MEDIUM] CWE-79 CVE-2017-7109: An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is af
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web
nvdapple
CVE-2024-54523P4MEDIUMCVSS 6.3fixed in 18.22025-01-27
CVE-2024-54523 [MEDIUM] CWE-787 CVE-2024-54523: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2017-7059P4MEDIUMCVSS 6.1fixed in 10.2.22017-07-20
CVE-2017-7059 [MEDIUM] CWE-79 CVE-2017-7059: A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safar
A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.
nvdapple
CVE-2022-32891P4MEDIUMCVSS 6.1fixed in 16.02023-02-27
CVE-2022-32891 [MEDIUM] CWE-1021 CVE-2022-32891: The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchO
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2026-28897P4MEDIUMCVSS 6.2fixed in 26.52026-05-11
CVE-2026-28897 [MEDIUM] CWE-121 CVE-2026-28897: A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 an
A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A local user may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2026-43666P4MEDIUMCVSS 6.2fixed in 26.52026-05-11
CVE-2026-43666 [MEDIUM] CWE-787 CVE-2026-43666: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2021-30682P4MEDIUMCVSS 5.5fixed in 14.62021-09-08
CVE-2021-30682 [MEDIUM] CVE-2021-30682: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.
nvdapple
CVE-2019-8540P4MEDIUMCVSS 5.5fixed in 12.2≥ unspecified, < tvOS 12.22019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2017-13804P4MEDIUMCVSS 5.5fixed in 11.12017-11-13
CVE-2017-13804 [MEDIUM] CWE-20 CVE-2017-13804: An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "StreamingZip" component. It allows remote attackers to write to unintended pathnames via a crafted ZIP archive.
nvdapple
CVE-2021-30773P4MEDIUMCVSS 5.5fixed in 14.7≥ unspecified, < 14.72021-09-08
CVE-2021-30773 [MEDIUM] CVE-2021-30773: An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS
An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.
nvd