Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL148HIGH1017MEDIUM768LOW68UNKNOWN35
Vulnerabilities
Page 19 of 102
CVE-2025-24230P3CRITICALCVSS 9.8fixed in 11.42025-03-31
CVE-2025-24230 [CRITICAL] CWE-125 CVE-2025-24230: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Playing a malicious audio file may lead to an unexpected app termination.
nvdapple
CVE-2025-24190P3CRITICALCVSS 9.8fixed in 11.42025-03-31
CVE-2025-24190 [CRITICAL] CWE-400 CVE-2025-24190: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvdapple
CVE-2016-1950P3HIGHCVSS 8.8≤ 2.12016-03-13
CVE-2016-1950 [HIGH] CWE-119 CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
nvdapple
CVE-2019-8527P3CRITICALCVSS 9.1fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8527 [CRITICAL] CWE-120 CVE-2019-8527: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macO
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2016-4448P3CRITICALCVSS 9.8≤ 2.2.12016-06-09
CVE-2016-4448 [CRITICAL] CWE-134 CVE-2016-4448: Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
nvdapple
CVE-2025-43234P3CRITICALCVSS 9.8fixed in 11.62025-07-30
CVE-2025-43234 [CRITICAL] CWE-20 CVE-2025-43234: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted texture may lead to unexpected app termination.
nvdapple
CVE-2025-24264P3CRITICALCVSS 9.8fixed in 11.42025-03-31
CVE-2025-24264 [CRITICAL] CWE-400 CVE-2025-24264: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43343P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43343 [CRITICAL] CWE-119 CVE-2025-43343: The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2021-1748P3HIGHCVSS 8.8fixed in 7.3≥ unspecified, < 7.32021-04-02
CVE-2021-1748 [HIGH] CWE-20 CVE-2021-1748: A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4,
A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
nvd
CVE-2020-9920P3CRITICALCVSS 9.1fixed in 6.2.8≥ unspecified, < watchOS 6.2.82020-10-22
CVE-2020-9920 [CRITICAL] CWE-22 CVE-2020-9920: A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iP
A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, watchOS 6.2.8. A malicious mail server may overwrite arbitrary mail files.
nvdapple
CVE-2019-8544P3HIGHCVSS 8.8fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8544 [HIGH] CWE-787 CVE-2019-8544: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8536P3HIGHCVSS 8.8fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8536 [HIGH] CWE-787 CVE-2019-8536: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8657P3HIGHCVSS 8.8fixed in 5.3≥ unspecified, < watchOS 5.32019-12-18
CVE-2019-8657 [HIGH] CWE-125 CVE-2019-8657: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. Parsing a maliciously crafted office document may lead to an unexpected application termination or arbitrary code execution.
nvdapple
CVE-2019-6217P3HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6217 [HIGH] CWE-787 CVE-2019-6217: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6226P3HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6226 [HIGH] CWE-787 CVE-2019-6226: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6216P3HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6216 [HIGH] CWE-787 CVE-2019-6216: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8553P3HIGHCVSS 8.8fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8553 [HIGH] CWE-787 CVE-2019-8553: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, t
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2. Clicking a malicious SMS link may lead to arbitrary code execution.
nvdapple
CVE-2018-4088P3HIGHCVSS 8.8fixed in 4.2.22018-04-03
CVE-2018-4088 [HIGH] CWE-119 CVE-2018-4088: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "WebKit" component. It allows
nvdapple
CVE-2018-4096P3HIGHCVSS 8.8fixed in 4.2.22018-04-03
CVE-2018-4096 [HIGH] CWE-119 CVE-2018-4096: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "WebKit" component. It allows
nvdapple
CVE-2019-8559P3HIGHCVSS 8.8fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8559 [HIGH] CWE-787 CVE-2019-8559: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple