Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL141HIGH1004MEDIUM758LOW68UNKNOWN65
Vulnerabilities
Page 18 of 102
CVE-2020-9983P3HIGHCVSS 8.8v7.02020-10-16
CVE-2020-9983 [HIGH] CWE-787 CVE-2020-9983: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Saf
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.
nvdapple
CVE-2021-1792P3HIGHCVSS 8.8fixed in 7.32021-04-02
CVE-2021-1792 [HIGH] CWE-125 CVE-2021-1792: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.
nvd
CVE-2019-6227P3HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6227 [HIGH] CWE-787 CVE-2019-6227: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2021-30707P3HIGHCVSS 8.8fixed in 7.52021-09-08
CVE-2021-30707 [HIGH] CWE-120 CVE-2021-30707: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6,
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvdapple
CVE-2021-30797P3HIGHCVSS 8.8fixed in 7.62021-09-08
CVE-2021-30797 [HIGH] CVE-2021-30797: This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS
This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2019-8583P3HIGHCVSS 8.8fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8583 [HIGH] CWE-787 CVE-2019-8583: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2020-9800P3HIGHCVSS 8.8fixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-06-09
CVE-2020-9800 [HIGH] CWE-843 CVE-2020-9800: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2016-4609P3CRITICALCVSS 9.8fixed in 2.2.22016-07-22
CVE-2016-4609 [CRITICAL] CVE-2016-4609: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-460
nvdapple
CVE-2016-4607P3CRITICALCVSS 9.8fixed in 2.2.22016-07-22
CVE-2016-4607 [CRITICAL] CWE-119 CVE-2016-4607: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4608, CVE-
nvdapple
CVE-2016-4610P3CRITICALCVSS 9.8v2.2.22016-07-18
CVE-2016-4610 [CRITICAL] CVE-2016-4610: watchOS 2.2.2
Apple Security Update: About the security content of watchOS 2.2.2
Product: watchOS
Version: 2.2.2
CVE: CVE-2016-4610
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple
CVE-2022-32845P3CRITICALCVSS 10.0fixed in 8.7≥ unspecified, < 8.7+1 more2022-09-23
CVE-2022-32845 [CRITICAL] CWE-693 CVE-2022-32845: This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPad
This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.
nvdapple
CVE-2016-4608P3CRITICALCVSS 9.8v2.2.22016-07-18
CVE-2016-4608 [CRITICAL] CVE-2016-4608: watchOS 2.2.2
Apple Security Update: About the security content of watchOS 2.2.2
Product: watchOS
Version: 2.2.2
CVE: CVE-2016-4608
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple
CVE-2022-42795P3HIGHCVSS 8.8fixed in 9.0≥ unspecified, < 9+1 more2022-11-01
CVE-2022-42795 [HIGH] CWE-787 CVE-2022-42795: A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS
A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 16, iOS 16, macOS Ventura 13, watchOS 9. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2022-22624P3HIGHCVSS 8.8v8.52022-03-14
CVE-2022-22624 [HIGH] CVE-2022-22624: watchOS 8.5
Apple Security Update: About the security content of watchOS 8.5
Product: watchOS
Version: 8.5
CVE: CVE-2022-22624
Component: WebKit Bugzilla 233172
apple
CVE-2023-42950P3HIGHCVSS 8.8fixed in 10.2≥ unspecified, < 10.22024-03-28
CVE-2023-42950 [HIGH] CWE-416 CVE-2023-42950: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2020-3878P3HIGHCVSS 7.8fixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-02-27
CVE-2020-3878 [HIGH] CWE-125 CVE-2020-3878: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2024-27859P3HIGHCVSS 8.8fixed in 10.42025-02-10
CVE-2024-27859 [HIGH] CWE-94 CVE-2024-27859: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2023-42970P3HIGHCVSS 8.8fixed in 10.0≥ unspecified, < 102025-04-11
CVE-2023-42970 [HIGH] CWE-416 CVE-2023-42970: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.
nvdapple
CVE-2017-2519P3CRITICALCVSS 9.8fixed in 3.2.22017-05-22
CVE-2017-2519 [CRITICAL] CVE-2017-2519: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvdapple
CVE-2017-7103P3CRITICALCVSS 9.8≤ 3.2.32017-10-23
CVE-2017-7103 [CRITICAL] CWE-119 CVE-2017-7103: An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affe
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic.
nvd