tvOS Apple tvOS Apple TV Operating System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apple tvOS.

Recent Apple tvOS Security Advisories

Advisory Title Published
149036 tvOS 27 - Apple Security Content September 14, 2026
128069 tvOS 26.6 - Apple Security Content July 27, 2026
127118 tvOS 26.5 - Apple Security Content May 11, 2026
126797 tvOS 26.4 - Apple Security Content March 24, 2026
126351 tvOS 26.3 - Apple Security Content February 11, 2026
125889 tvOS 26.2 - Apple Security Content December 12, 2025
125637 tvOS 26.1 - Apple Security Content November 3, 2025
125114 tvOS 26 - Apple Security Content September 15, 2025
124153 tvOS 18.6 - Apple Security Content July 29, 2025
122720 tvOS 18.5 - Apple Security Content May 12, 2025

Apple tvOS EOL Dates

Ensure that you are using a supported version of Apple tvOS. Here are some end of life, and end of support dates for Apple tvOS.

Release EOL Date Status
26 -
Active

18 September 15, 2025
EOL

Apple tvOS 18 became EOL in 2025.

17 September 16, 2024
EOL

Apple tvOS 17 became EOL in 2024.

16 September 18, 2023
EOL

Apple tvOS 16 became EOL in 2023.

15 September 12, 2022
EOL

Apple tvOS 15 became EOL in 2022.

14 September 20, 2021
EOL

Apple tvOS 14 became EOL in 2021.

13 September 16, 2020
EOL

Apple tvOS 13 became EOL in 2020.

12 September 24, 2019
EOL

Apple tvOS 12 became EOL in 2019.

11 September 17, 2018
EOL

Apple tvOS 11 became EOL in 2018.

10 September 19, 2017
EOL

Apple tvOS 10 became EOL in 2017.

9 September 13, 2016
EOL

Apple tvOS 9 became EOL in 2016.

By the Year

In 2026 there have been 282 vulnerabilities in Apple tvOS with an average score of 7.2 out of ten. Last year, in 2025 tvOS had 207 security vulnerabilities published. That is, 75 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.43.




Year Vulnerabilities Average Score
2026 282 7.18
2025 207 6.76
2024 152 6.76
2023 133 7.00
2022 145 7.38
2021 242 7.15
2020 216 7.49
2019 262 7.87
2018 67 7.81

It may take a day or so for new tvOS vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple tvOS Security Vulnerabilities

Apple OSes Type Confusion DFS before 27 via memory handling
CVE-2026-65409 - September 14, 2026

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause a denial of service.

Apple OS kernel use-after-free via NFS (fixed in 26.7/27)
CVE-2026-43686 - September 14, 2026

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory corruption.

Apple OS OOB Write in File Processing (Fixed in iOS 27, macOS 15.8)
CVE-2026-84575 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination.

Memory init flaw in Apple OS (fixed in iOS 26.7, iPadOS 26.7, macOS 27)
CVE-2026-65405 - September 14, 2026

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout.

Apple OS Kernel Race Condition Leading to Termination (fixed iOS 18.7.10)
CVE-2026-64717 - September 14, 2026

A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

Apple iOS Persistent Account ID Disclosure via State Management
CVE-2026-86895 - September 14, 2026

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.

Apple OS OOB Write via Malicious 3D Model (Fixed in 26.7/27)
CVE-2026-84611 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.

Apple OSs: Race Condition Causing Unexpected Termination (CVE202684492)
CVE-2026-84492 - September 14, 2026

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

Race condition in Apple iOS 26.7 allows kernel-priv exec via sandboxed app
CVE-2026-84607 - September 14, 2026

A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privileges.

Apple OS Font Engine OOB Read Exposes Process Memory
CVE-2026-84596 - September 14, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.

Out-of-Bounds Read in Apple OS Font Parsing (CVE-2026-84597)
CVE-2026-84597 - September 14, 2026

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.

Apple iOS 26.7/iPadOS 26.7 App Data Leakage Vulnerability
CVE-2026-43664 - September 14, 2026

This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data.

Use-After-Free in Apple OS 26.6 (iOS, macOS, tvOS, watchOS, iPadOS)
CVE-2026-43808 - September 14, 2026

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Auth Issue: Motion Data from Headphones Access without Consent (iOS 26.7+)
CVE-2026-43737 - September 14, 2026

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent.

Apple OS ImageIO OOB Write pre 26.7
CVE-2026-86882 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected process termination.

Apple OS Kernel Memory Disclosure via NFS Client (CVE-2026-43687)
CVE-2026-43687 - September 14, 2026

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory.

Kernel Memory OOB Write in Apple OS (iOS <26.7, macOS <15.8)
CVE-2026-84523 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or write kernel memory.

Out-of-Bounds Access in Apple OS Kernels before 26.6.1/iPadOS, 15.8/Sequoia
CVE-2026-64736 - September 14, 2026

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.

Race Condition in Apple OS leading to unexpected termination (fixed 26.727)
CVE-2026-84630 - September 14, 2026

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

Apple OS Kernel Memory Disclosure via Improper Redaction (iOS 26.6+)
CVE-2026-65371 - September 14, 2026

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.

Apple OS State Mgmt Info Disclosure Fixed in iOS 26.7
CVE-2026-84626 - September 14, 2026

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to identify what other apps a user has installed.

Apple OS Image Processing OOB Write (CVE-2026-65395) before 26.7
CVE-2026-65395 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted image may result in memory corruption.

Apple OS 27: Kernel Race Condition Allowing Local User to Read Kernel Memory
CVE-2026-65415 - September 14, 2026

A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel memory.

Apple OS Permission Leak: App Can Read Device Name via API
CVE-2026-86893 - September 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to read device name.

Apple OS authorization flaw before iOS 27 via state mgmt
CVE-2026-84617 - September 14, 2026

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27. An app may be able to access sensitive user data.

Apple OS OOB Read via Input Validation in Kernel
CVE-2026-86903 - September 14, 2026

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to disclose kernel memory.

Apple OS OOB Write (iOS 26.7/27, macOS 15.8/27)
CVE-2026-28966 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted file may lead to unexpected app termination.

Apple OS Race Condition Causes AppInduced Termination, Fixed in iOS 26.7
CVE-2026-65360 - September 14, 2026

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

Apple OS OOB Read in iOS 26.7/iPadOS 26.7, macOS Sequoia 15.8
CVE-2026-84532 - September 14, 2026

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Opening a maliciously crafted file may cause unexpected process termination or disclose process memory.

Apple OS OOB Read in Font File Parser Fixed in iOS 27/macOS 15.8
CVE-2026-84524 - September 14, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font file may lead to unexpected app termination.

Apple OS: Cryptographic Integrity Check Vulnerability Enabling Traffic Tampering
CVE-2026-84533 - September 14, 2026

A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An attacker in a privileged network position may be able to modify network traffic.

Apple OS File Permission Escalation (iOS 27, macOS 15.8)
CVE-2026-43785 - September 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to read.

Apple OS Uninitialized Memory Leak via Image CVE-2026-84564 (iOS 26.7+)
CVE-2026-84564 - September 14, 2026

An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may result in disclosure of process memory.

Apple OS Authorization Flaw Fixed with State Management
CVE-2026-84636 - September 14, 2026

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

Apple OS OOB Buffer VU CVE-2026-65398: Kernel Crash
CVE-2026-65398 - September 14, 2026

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.

Apple OS Memory Corruption Vulnerability iOS<26.7, macOS<27
CVE-2026-65377 - September 14, 2026

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

Apple iOS/macOS tvOS 27 Integer Overflow in 3D Model Processing
CVE-2026-84620 - September 14, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.

Apple OS permission flaw reads persistent acct ID before v27
CVE-2026-86888 - September 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account identifier.

Apple OSes Memory Handling Bug Causing Kernel Write (Fixed 26.6)
CVE-2026-65357 - September 14, 2026

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

Apple OS Shortcuts Auth Bypass via StateMgmt
CVE-2026-84600 - September 14, 2026

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A malicious shortcut may be able to send messages without user confirmation.

Apple OS Type Confusion CVE-2026-84616 (Fixed in iOS 27, macOS 27, etc.)
CVE-2026-84616 - September 14, 2026

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

Apple operating systems location leakage (before 26.7)
CVE-2026-84513 - September 14, 2026

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A malicious application may be able to determine a user's current location.

Apple OS OOB Write before 26.7 leads to Code Exec
CVE-2026-65414 9.8 - Critical - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.

Memory Corruption

Apple OS Use-After-Free in iOS 26.7/iPadOS 26.7, iOS 27, macOS 27
CVE-2026-65402 - September 14, 2026

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

Apple OS iOS 27 Permissions Issue Allows App Access to Sensitive Data
CVE-2026-86884 - September 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An app may be able to access sensitive user data.

Apple OS 26.7-27 Auth Leak via State Management
CVE-2026-84615 - September 14, 2026

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, tvOS 27, visionOS 27. An app may be able to access sensitive user data.

Apple iOS/macOS Kernel OOB Write CVE-2026-28968 (Fixed in 26.727)
CVE-2026-28968 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.

Apple OS Race Condition Fix iOS 27, macOS 15.8 & Others
CVE-2026-65358 - September 14, 2026

A race condition was addressed with improved state handling. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination.

Apple OS Image Overflow (CVE-2026-84571)
CVE-2026-84571 - September 14, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected app termination.

Out-of-Bounds Write in Apple 3D Scene Processing (iOS 26.7+, macOS 27+)
CVE-2026-84526 - September 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D scene may lead to unexpected process termination.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple tvOS or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple tvOS
Apple TV Operating System

subscribe