cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 23 of 102
CVE-2016-4738P3HIGHCVSS 8.8fixed in 3.02016-09-25
CVE-2016-4738 [HIGH] CWE-119 CVE-2016-4738: libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remot libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
nvd
CVE-2016-9841P3CRITICALCVSS 9.8fixed in 42017-05-23
CVE-2016-9841 [CRITICAL] CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by levera inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2025-24237P3CRITICALCVSS 9.8fixed in 11.42025-03-31
CVE-2025-24237 [CRITICAL] CWE-120 CVE-2025-24237: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and i A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination.
nvdapple
CVE-2022-22632P3CRITICALCVSS 9.8fixed in 8.5≥ unspecified, < 8.52022-03-18
CVE-2022-22632 [CRITICAL] CVE-2022-22632: A logic issue was addressed with improved state management. This issue is fixed in tvOS 15.4, iOS 15 A logic issue was addressed with improved state management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, watchOS 8.5, macOS Monterey 12.3. A malicious application may be able to elevate privileges.
nvdapple
CVE-2024-40815P3HIGHCVSS 7.5fixed in 10.62024-07-29
CVE-2024-40815 [HIGH] CWE-362 CVE-2024-40815: A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvdapple
CVE-2022-42845P3HIGHCVSS 7.2fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42845 [HIGH] CWE-787 CVE-2022-42845: The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monte The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2020-3843P3HIGHCVSS 8.8fixed in 5.3.72020-02-27
CVE-2020-3843 [HIGH] CWE-787 CVE-2020-3843: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4.7, watchOS 5.3.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2018-4124P3CRITICALCVSS 9.8fixed in 4.2.32018-04-03
CVE-2018-4124 [CRITICAL] CWE-119 CVE-2018-4124: An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.6 is affected. macOS before 10.13.3 Supplemental Update is affected. tvOS before 11.2.6 is affected. watchOS before 4.2.3 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly
nvdapple
CVE-2025-43342P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43342 [CRITICAL] CWE-20 CVE-2025-43342: A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 a A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2017-15412P3HIGHCVSS 8.8v4.32018-03-29
CVE-2017-15412 [HIGH] CVE-2017-15412: watchOS 4.3 Apple Security Update: About the security content of watchOS 4.3 Product: watchOS Version: 4.3 CVE: CVE-2017-15412 Component: Kernel Impact: A malicious application may be able to determine kernel memory layout Description: An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.
apple
CVE-2021-21779P3HIGHCVSS 8.8v7.52021-05-24
CVE-2021-21779 [HIGH] CVE-2021-21779: watchOS 7.5 Apple Security Update: About the security content of watchOS 7.5 Product: watchOS Version: 7.5 CVE: CVE-2021-21779 Component: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management.
apple
CVE-2026-64726P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64726 [CRITICAL] CWE-119 CVE-2026-64726: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.
nvd
CVE-2017-7068P3HIGHCVSS 8.8≤ 3.2.22017-07-20
CVE-2017-7068 [HIGH] CWE-119 CVE-2017-7068: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via
nvdapple
CVE-2016-7589P3HIGHCVSS 8.8≤ 2.2.22017-02-20
CVE-2016-7589 [HIGH] CWE-119 CVE-2016-7589: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
nvdapple
CVE-2019-8602P3HIGHCVSS 7.8fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8602 [HIGH] CWE-787 CVE-2019-8602: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to elevate privileges.
nvdapple
CVE-2019-8577P3HIGHCVSS 7.8fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8577 [HIGH] CWE-119 CVE-2019-8577: An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 12 An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. An application may be able to gain elevated privileges.
nvdapple
CVE-2020-15969P3HIGHCVSS 8.8fixed in 7.22020-11-03
CVE-2020-15969 [HIGH] CWE-416 CVE-2020-15969: Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potenti Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-0802P3HIGHCVSS 8.8≤ 2.12016-02-07
CVE-2016-0802 [HIGH] CWE-20 CVE-2016-0802: The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6. The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
nvdapple
CVE-2019-8639P3HIGHCVSS 8.8fixed in 5.2≥ unspecified, < 5.22020-10-27
CVE-2019-8639 [HIGH] CWE-787 CVE-2019-8639: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 5.2, iCloud for Windows 7.11, iOS 12.2, iTunes 12.9.4 for Windows, Safari 12.1. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8638P3HIGHCVSS 8.8fixed in 5.2≥ unspecified, < 5.22020-10-27
CVE-2019-8638 [HIGH] CWE-787 CVE-2019-8638: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 5.2, iCloud for Windows 7.11, iOS 12.2, iTunes 12.9.4 for Windows, Safari 12.1. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
Apple watchOS vulnerabilities | cvebase