TV OS Apple TV OS Apple TV Operating System

Do you want an email whenever new security vulnerabilities are reported in Apple TV OS?

Recent Apple TV OS Security Advisories

Advisory Title Published
HT212876 tvOS 15.1 Security Content October 25, 2021
HT212815 tvOS 15 Security Content September 20, 2021
HT212604 tvOS 14.7 Security Content July 19, 2021
HT212532 tvOS 14.6 Security Content May 24, 2021
HT212323 tvOS 14.5 Security Content April 26, 2021
HT212149 tvOS 14.4 Security Content January 26, 2021
HT212005 tvOS 14.3 Security Content December 14, 2020
HT211930 tvOS 14.2 Security Content November 5, 2020
HT211843 tvOS 14.0 Security Content September 16, 2020
HT211290 tvOS 13.4.8 Security Content July 15, 2020

By the Year

In 2021 there have been 200 vulnerabilities in Apple TV OS with an average score of 7.2 out of ten. Last year TV OS had 169 security vulnerabilities published. That is, 31 more vulnerabilities have already been reported in 2021 as compared to last year. Last year, the average CVE base score was greater by 0.25

Year Vulnerabilities Average Score
2021 200 7.20
2020 169 7.46
2019 250 7.96
2018 43 8.18

It may take a day or so for new TV OS vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple TV OS Security Vulnerabilities

This issue was addressed with improved checks

CVE-2021-30808 5.5 - Medium - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A malicious application may be able to modify protected parts of the file system.

A use after free issue was addressed with improved memory management

CVE-2021-30809 8.8 - High - October 28, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A memory corruption issue was addressed with improved input validation

CVE-2021-30814 7.8 - High - October 28, 2021

A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.

Memory Corruption

A type confusion issue was addressed with improved state handling

CVE-2021-30818 8.8 - High - October 28, 2021

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Object Type Confusion

A logic issue was addressed with improved restrictions

CVE-2021-30823 6.5 - Medium - October 28, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.

An out-of-bounds read was addressed with improved input validation

CVE-2021-30831 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted font may result in the disclosure of process memory.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30834 7.8 - High - October 28, 2021

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, Security Update 2021-007 Catalina. Processing a malicious audio file may result in unexpected application termination or arbitrary code execution.

An out-of-bounds read was addressed with improved input validation

CVE-2021-30836 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.

Out-of-bounds Read

This issue was addressed with improved checks

CVE-2021-30840 7.8 - High - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30847 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

Multiple memory corruption issues were addressed with improved memory handling

CVE-2021-30849 7.8 - High - October 19, 2021

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

This issue was addressed with improved checks

CVE-2021-30835 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30841 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30842 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30843 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

An access issue was addressed with improved access restrictions

CVE-2021-30850 5.5 - Medium - October 19, 2021

An access issue was addressed with improved access restrictions. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6, tvOS 15. A user may gain access to protected parts of the file system.

Exposure of Resource to Wrong Sphere

A memory corruption issue was addressed with improved memory handling

CVE-2021-30846 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

An authorization issue was addressed with improved state management

CVE-2021-30810 4.3 - Medium - October 19, 2021

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.

AuthZ

A memory consumption issue was addressed with improved memory handling

CVE-2021-30837 7.8 - High - October 19, 2021

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An application may be able to execute arbitrary code with kernel privileges.

A logic issue was addressed with improved restrictions

CVE-2021-1826 6.1 - Medium - September 08, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to universal cross site scripting.

XSS

An input validation issue was addressed with improved input validation

CVE-2021-1825 6.1 - Medium - September 08, 2021

An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.

XSS

A logic issue was addressed with improved restrictions

CVE-2021-1822 5.5 - Medium - September 08, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.

Exposure of Resource to Wrong Sphere

A buffer overflow may result in arbitrary code execution

CVE-2021-1770 9.8 - Critical - September 08, 2021

A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management.

Buffer Overflow

A logic issue was addressed with improved state management

CVE-2021-30715 7.5 - High - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted message may lead to a denial of service.

This issue was addressed with improved checks

CVE-2021-1843 7.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted image may lead to arbitrary code execution.

A memory initialization issue was addressed with improved memory handling

CVE-2021-1820 6.5 - Medium - September 08, 2021

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure of process memory.

Exposure of Resource to Wrong Sphere

A memory corruption issue was addressed with improved state management

CVE-2021-1817 8.8 - High - September 08, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

Copied files may not have the expected file permissions

CVE-2021-1832 5.5 - Medium - September 08, 2021

Copied files may not have the expected file permissions. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. The issue was addressed with improved permissions logic.

Incorrect Default Permissions

A logic issue was addressed with improved restrictions

CVE-2021-1836 5.5 - Medium - September 08, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A local user may be able to create or modify privileged files.

Improper Privilege Management

A parsing issue in the handling of directory paths was addressed with improved path validation

CVE-2021-1740 5.5 - Medium - September 08, 2021

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.

Directory traversal

A parsing issue in the handling of directory paths was addressed with improved path validation

CVE-2021-1739 5.5 - Medium - September 08, 2021

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.

Directory traversal

A parsing issue in the handling of directory paths was addressed with improved path validation

CVE-2021-1815 5.5 - Medium - September 08, 2021

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.

Directory traversal

A logic issue was addressed with improved state management

CVE-2021-1811 6.5 - Medium - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory.

A memory corruption issue was addressed with improved validation

CVE-2021-1809 7.5 - High - September 08, 2021

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to read restricted memory.

Out-of-bounds Read

A memory corruption issue was addressed with improved validation

CVE-2021-1808 7.5 - High - September 08, 2021

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to read restricted memory.

Out-of-bounds Read

A memory corruption issue was addressed with improved state management

CVE-2021-30710 7.1 - High - September 08, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may cause a denial of service or potentially disclose memory contents.

Memory Corruption

This issue was addressed with improved checks

CVE-2021-30707 8.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted audio file may lead to arbitrary code execution.

Classic Buffer Overflow

This issue was addressed with improved environment sanitization

CVE-2021-30677 8.8 - High - September 08, 2021

This issue was addressed with improved environment sanitization. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to break out of its sandbox.

A memory corruption issue was addressed with improved state management

CVE-2021-30665 8.8 - High - September 08, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Buffer Overflow

A use after free issue was addressed with improved memory management

CVE-2021-1864 9.8 - Critical - September 08, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.

Dangling pointer

Processing a maliciously crafted image may lead to arbitrary code execution

CVE-2021-1858 7.8 - High - September 08, 2021

Processing a maliciously crafted image may lead to arbitrary code execution. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds write issue was addressed with improved bounds checking.

Memory Corruption

A buffer overflow was addressed with improved bounds checking

CVE-2021-1816 7.8 - High - September 08, 2021

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to execute arbitrary code with kernel privileges.

Buffer Overflow

An issue in code signature validation was addressed with improved checks

CVE-2021-1849 7.5 - High - September 08, 2021

An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.

Improper Verification of Cryptographic Signature

A logic issue was addressed with improved state management

CVE-2021-1851 8.8 - High - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.

Improper Privilege Management

A memory corruption issue was addressed with improved validation

CVE-2021-1882 9.8 - Critical - September 08, 2021

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to gain elevated privileges.

Memory Corruption

A logic issue was addressed with improved state management

CVE-2021-1868 7.8 - High - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.

Improper Privilege Management

This issue was addressed with improved checks

CVE-2021-1883 5.5 - Medium - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted server messages may lead to heap corruption.

Improper Validation of Integrity Check Value

A race condition was addressed with additional validation

CVE-2021-30652 7 - High - September 08, 2021

A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.

Race Condition

An out-of-bounds read was addressed with improved bounds checking

CVE-2021-30660 7.5 - High - September 08, 2021

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to disclose kernel memory.

Out-of-bounds Read

An out-of-bounds read was addressed with improved input validation

CVE-2021-1881 7.8 - High - September 08, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted font file may lead to arbitrary code execution.

Out-of-bounds Read

An out-of-bounds read was addressed with improved bounds checking

CVE-2021-1885 7.8 - High - September 08, 2021

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.

Out-of-bounds Read

An out-of-bounds read was addressed with improved bounds checking

CVE-2021-30687 5.5 - Medium - September 08, 2021

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted image may lead to disclosure of user information.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30697 5.5 - Medium - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local user may be able to leak sensitive user information.

This issue was addressed with improved checks

CVE-2021-30700 5.5 - Medium - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted image may lead to disclosure of user information.

This issue was addressed with improved checks

CVE-2021-30701 7.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted image may lead to arbitrary code execution.

A double free issue was addressed with improved memory management

CVE-2021-30703 7.8 - High - September 08, 2021

A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.

Double-free

A logic issue was addressed with improved state management

CVE-2021-30704 7.8 - High - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary code with kernel privileges.

This issue was addressed with improved checks

CVE-2021-30705 5.5 - Medium - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted ASTC file may disclose memory contents.

A memory initialization issue was addressed with improved memory handling

CVE-2021-1857 6.5 - Medium - September 08, 2021

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.

Improper Initialization

A validation issue was addressed with improved logic

CVE-2021-1813 7.8 - High - September 08, 2021

A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to gain root privileges.

Improper Privilege Management

An integer overflow was addressed with improved input validation

CVE-2021-30663 8.8 - High - September 08, 2021

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.

Integer Overflow or Wraparound

A race condition was addressed with improved locking

CVE-2021-1884 5.9 - Medium - September 08, 2021

A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.

Race Condition

A double free issue was addressed with improved memory management

CVE-2021-1875 7.8 - High - September 08, 2021

A double free issue was addressed with improved memory management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted file may lead to heap corruption.

Double-free

Processing a maliciously crafted image may lead to disclosure of user information

CVE-2021-30706 5.5 - Medium - September 08, 2021

Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.

Out-of-bounds Read

Processing a maliciously crafted audio file may disclose restricted memory

CVE-2021-1846 5.5 - Medium - September 08, 2021

Processing a maliciously crafted audio file may disclose restricted memory. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds read was addressed with improved input validation.

Out-of-bounds Read

A memory initialization issue was addressed with improved memory handling

CVE-2021-1860 6.5 - Medium - September 08, 2021

A memory initialization issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able to disclose kernel memory.

Improper Initialization

This issue was addressed with improved checks

CVE-2021-30653 7.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.

Injection

A use after free issue was addressed with improved memory management

CVE-2021-30661 8.8 - High - September 08, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Dangling pointer

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2021-30664 7.8 - High - September 08, 2021

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.

Memory Corruption

A logic issue was addressed with improved restrictions

CVE-2021-30682 5.5 - Medium - September 08, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.

This issue was addressed with improved checks

CVE-2021-30685 5.5 - Medium - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Parsing a maliciously crafted audio file may lead to disclosure of user information.

An out-of-bounds read was addressed with improved bounds checking

CVE-2021-30686 5.5 - Medium - September 08, 2021

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted audio file may disclose restricted memory.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30689 6.1 - Medium - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

XSS

Processing a maliciously crafted font may result in the disclosure of process memory

CVE-2021-30755 6.5 - Medium - September 08, 2021

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5. An out-of-bounds read was addressed with improved input validation.

Out-of-bounds Read

A buffer overflow was addressed with improved bounds checking

CVE-2021-30785 7.8 - High - September 08, 2021

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted image may lead to arbitrary code execution.

Classic Buffer Overflow

A logic issue was addressed with improved validation

CVE-2021-30774 7.8 - High - September 08, 2021

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. A malicious application may be able to gain root privileges.

An integer overflow was addressed through improved input validation

CVE-2021-30760 7.8 - High - September 08, 2021

An integer overflow was addressed through improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.

Integer Overflow or Wraparound

A use after free issue was addressed with improved memory management

CVE-2021-30795 8.8 - High - September 08, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2021-30780 7.8 - High - September 08, 2021

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A malicious application may be able to gain root privileges.

Memory Corruption

Processing a maliciously crafted file may lead to arbitrary code execution

CVE-2021-30764 7.8 - High - September 08, 2021

Processing a maliciously crafted file may lead to arbitrary code execution. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. This issue was addressed with improved checks.

An out-of-bounds write was addressed with improved input validation

CVE-2021-30743 7.8 - High - September 08, 2021

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted image may lead to arbitrary code execution.

Memory Corruption

A logic issue was addressed with improved validation

CVE-2021-30740 7.8 - High - September 08, 2021

A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. A malicious application may be able to execute arbitrary code with kernel privileges.

A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code

CVE-2021-30737 8.8 - High - September 08, 2021

A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, iOS 12.5.4, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted certificate may lead to arbitrary code execution.

Memory Corruption

A buffer overflow was addressed with improved size validation

CVE-2021-30736 7.8 - High - September 08, 2021

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An application may be able to execute arbitrary code with kernel privileges.

Classic Buffer Overflow

Multiple memory corruption issues were addressed with improved memory handling

CVE-2021-30734 8.8 - High - September 08, 2021

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A logic issue was addressed with improved restrictions

CVE-2021-30720 5.4 - Medium - September 08, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.

authentification

This issue was addressed with improved checks

CVE-2021-30797 8.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code execution.

A stack overflow was addressed with improved input validation

CVE-2021-30759 7.8 - High - September 08, 2021

A stack overflow was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.

Memory Corruption

A type confusion issue was addressed with improved state handling

CVE-2021-30758 8.8 - High - September 08, 2021

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

Object Type Confusion

An out-of-bounds read was addressed with improved input validation

CVE-2021-30733 5.5 - Medium - September 08, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted font may result in the disclosure of process memory.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30727 5.5 - Medium - September 08, 2021

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. A malicious application may be able to modify protected parts of the file system.

Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins

CVE-2021-30744 6.1 - Medium - September 08, 2021

Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

XSS

An out-of-bounds read was addressed with improved input validation

CVE-2021-30789 7.8 - High - September 08, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.

Out-of-bounds Read

This issue was addressed with improved checks

CVE-2021-30781 7.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. A local attacker may be able to cause unexpected application termination or arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30779 7.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing a maliciously crafted image may lead to arbitrary code execution.

A logic issue was addressed with improved validation

CVE-2021-30776 5.5 - Medium - September 08, 2021

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Playing a malicious audio file may lead to an unexpected application termination.

Improper Input Validation

An issue in code signature validation was addressed with improved checks

CVE-2021-30773 5.5 - Medium - September 08, 2021

An issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious application may be able to bypass code signing checks.

A logic issue was addressed with improved validation

CVE-2021-30768 5.5 - Medium - September 08, 2021

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.

A use after free issue was addressed with improved memory management

CVE-2021-30802 8.8 - High - September 08, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A memory corruption issue was addressed with improved state management

CVE-2021-30775 7.8 - High - September 08, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Processing a maliciously crafted audio file may lead to arbitrary code execution.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple Watch OS or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple TV OS
Apple TV Operating System

subscribe