cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL141HIGH1004MEDIUM758LOW68UNKNOWN65

Vulnerabilities

Page 17 of 102
CVE-2023-23518P3HIGHCVSS 8.8fixed in 9.3≥ unspecified, < 9.32023-02-27
CVE-2023-23518 [HIGH] CWE-787 CVE-2023-23518: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2023-23517P3HIGHCVSS 8.8fixed in 9.3≥ unspecified, < 9.32023-02-27
CVE-2023-23517 [HIGH] CWE-119 CVE-2023-23517: The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2018-4331P3CRITICALCVSS 9.8fixed in 5.02019-04-03
CVE-2018-4331 [CRITICAL] CWE-119 CVE-2018-4331: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2022-26710P3HIGHCVSS 8.8fixed in 8.6≥ unspecified, < 8.6+1 more2022-11-01
CVE-2022-26710 [HIGH] CWE-416 CVE-2022-26710: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, tvOS 15.5, watchOS 8.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-26709P3HIGHCVSS 8.8fixed in 8.6≥ unspecified, < 8.6+1 more2022-11-01
CVE-2022-26709 [HIGH] CWE-416 CVE-2022-26709: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2024-27851P3HIGHCVSS 8.8fixed in 10.52024-06-10
CVE-2024-27851 [HIGH] CWE-119 CVE-2024-27851: The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 an The issue was addressed with improved bounds checks. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2026-43715P3HIGHCVSS 8.8fixed in 26.62026-06-29
CVE-2026-43715 [HIGH] CWE-416 CVE-2026-43715: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2023-42866P3HIGHCVSS 8.8fixed in 9.6≥ unspecified, < 9.62024-01-10
CVE-2023-42866 [HIGH] CVE-2023-42866: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iO The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2024-54499P3HIGHCVSS 8.8fixed in 11.22025-01-27
CVE-2024-54499 [HIGH] CWE-416 CVE-2024-54499: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30993P3HIGHCVSS 8.1fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30993 [HIGH] CWE-120 CVE-2021-30993: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mo A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. An attacker in a privileged network position may be able to execute arbitrary code.
nvdapple
CVE-2019-6235P3CRITICALCVSS 10.0≥ unspecified, < watchOS 5.1.32019-03-04
CVE-2019-6235 [CRITICAL] CWE-787 CVE-2019-6235: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple
CVE-2024-56171P3HIGHCVSS 7.8v11.42025-04-01
CVE-2024-56171 [HIGH] CVE-2024-56171: watchOS 11.4 Apple Security Update: About the security content of watchOS 11.4 Product: watchOS Version: 11.4 CVE: CVE-2024-56171 Component: CVE-2024-56171 Impact: An app may be able to break out of its sandbox Description: This issue was addressed through improved state management.
apple
CVE-2019-5608P3CRITICALCVSS 9.8v5.22019-03-27
CVE-2019-5608 [CRITICAL] CVE-2019-5608: watchOS 5.2 Apple Security Update: About the security content of watchOS 5.2 Product: watchOS Version: 5.2 CVE: CVE-2019-5608 Component: Kernel Impact: A remote attacker may be able to alter network traffic data Description: A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with improved memory management.
apple
CVE-2020-3911P3CRITICALCVSS 9.8fixed in 6.2≥ unspecified, < watchOS 6.22020-04-01
CVE-2020-3911 [CRITICAL] CWE-120 CVE-2020-3911: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and i A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.
nvd
CVE-2020-3910P3CRITICALCVSS 9.8fixed in 6.2≥ unspecified, < watchOS 6.22020-04-01
CVE-2020-3910 [CRITICAL] CWE-120 CVE-2020-3910: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and i A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.
nvd
CVE-2024-54534P3CRITICALCVSS 9.8fixed in 11.22024-12-12
CVE-2024-54534 [CRITICAL] CWE-787 CVE-2024-54534: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
nvd
CVE-2017-2415P3HIGHCVSS 8.8≤ 3.1.32017-04-02
CVE-2017-2415 [HIGH] CVE-2017-2415: An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 i An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code by leveraging an unspecified "type confusion."
nvdapple
CVE-2020-9893P3HIGHCVSS 8.8fixed in 6.2.8≥ unspecified, < watchOS 6.2.82020-10-16
CVE-2020-9893 [HIGH] CWE-416 CVE-2020-9893: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2020-9951P3HIGHCVSS 8.8fixed in 7.02020-10-16
CVE-2020-9951 [HIGH] CWE-416 CVE-2020-9951: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2021-1851P3HIGHCVSS 8.8fixed in 7.4≥ unspecified, < 7.42021-09-08
CVE-2021-1851 [HIGH] CWE-269 CVE-2021-1851: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.
nvd
Apple watchOS vulnerabilities | cvebase