cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 24 of 102
CVE-2022-26763P3HIGHCVSS 7.8fixed in 8.6≥ unspecified, < 8.6+4 more2022-05-26
CVE-2022-26763 [HIGH] CWE-119 CVE-2022-26763: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tv An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious application may be able to execute arbitrary code with system privileges.
nvdapple
CVE-2024-54512P3CRITICALCVSS 9.1fixed in 11.22025-01-27
CVE-2024-54512 [CRITICAL] CWE-863 CVE-2024-54512: The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 1 The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A system binary could be used to fingerprint a user's Apple Account.
nvd
CVE-2017-13849P4MEDIUMCVSS 5.5PoCfixed in 4.12017-11-13
CVE-2017-13849 [MEDIUM] CWE-20 CVE-2017-13849: An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.
nvdapple
CVE-2016-7663P3CRITICALCVSS 9.8≤ 2.2.22017-02-20
CVE-2016-7663 [CRITICAL] CWE-119 CVE-2016-7663: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreFoundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted string.
nvdapple
CVE-2021-30849P3HIGHCVSS 7.8fixed in 8.0≥ unspecified, < 82021-10-19
CVE-2021-30849 [HIGH] CWE-787 CVE-2021-30849: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2018-16860P3HIGHCVSS 7.5v5.32019-07-22
CVE-2018-16860 [HIGH] CVE-2018-16860: watchOS 5.3 Apple Security Update: About the security content of watchOS 5.3 Product: watchOS Version: 5.3 CVE: CVE-2018-16860 Component: Heimdal Impact: An issue existed in Samba that may allow attackers to perform unauthorized actions by intercepting communications between services Description: This issue was addressed with improved checks to prevent unauthorized actions.
apple
CVE-2015-7987P3CRITICALCVSS 9.8fixed in 2.12016-06-26
CVE-2015-7987 [CRITICAL] CWE-119 CVE-2015-7987: Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write t Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import, or (4) CopyNSEC3ResourceRecord function.
nvdapple
CVE-2018-4332P3CRITICALCVSS 9.8fixed in 5.02019-04-03
CVE-2018-4332 [CRITICAL] CWE-119 CVE-2018-4332: A memory corruption issue was addressed with improved memory handling. This issue affected versions A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2019-8749P3CRITICALCVSS 9.8fixed in 6.0≥ unspecified, < 62020-10-27
CVE-2019-8749 [CRITICAL] CWE-787 CVE-2019-8749: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.
nvd
CVE-2019-8756P3CRITICALCVSS 9.8fixed in 6.0≥ unspecified, < 62020-10-27
CVE-2019-8756 [CRITICAL] CWE-787 CVE-2019-8756: Multiple memory corruption issues were addressed with improved input validation. This issue is fixed Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13, iCloud for Windows 7.14, iCloud for Windows 10.7, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, watchOS 6, iTunes 12.10.1 for Windows. Multiple issues in libxml2.
nvd
CVE-2025-30426P3CRITICALCVSS 9.8fixed in 11.42025-03-31
CVE-2025-30426 [CRITICAL] CWE-200 CVE-2025-30426: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to enumerate a user's installed apps.
nvdapple
CVE-2025-43359P3CRITICALCVSS 9.8fixed in 26.0fixed in 262025-09-15
CVE-2025-43359 [CRITICAL] CWE-670 CVE-2025-43359: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A UDP server socket bound to a local interface may become bound to all interfaces.
nvdapple
CVE-2016-1807P4MEDIUMCVSS 5.1PoCfixed in 2.2.12016-05-20
CVE-2016-1807 [MEDIUM] CWE-362 CVE-2016-1807: Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS bef Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to obtain sensitive information from kernel memory via unspecified vectors.
nvdapple
CVE-2018-4191P3HIGHCVSS 8.8fixed in 5.02019-04-03
CVE-2018-4191 [HIGH] CWE-119 CVE-2018-4191: A memory corruption issue was addressed with improved validation. This issue affected versions prior A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2021-30939P3HIGHCVSS 7.8fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30939 [HIGH] CWE-125 CVE-2021-30939: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvdapple
CVE-2018-4085P3HIGHCVSS 8.8fixed in 4.2.22018-04-03
CVE-2018-4085 [HIGH] CWE-119 CVE-2018-4085: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "QuartzCore" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) vi
nvdapple
CVE-2021-36690P3HIGHCVSS 7.5fixed in 9.02021-08-24
CVE-2021-36690 [HIGH] CVE-2021-36690: A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the id A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem
nvd
CVE-2024-54525P3HIGHCVSS 8.8fixed in 11.22025-03-17
CVE-2024-54525 [HIGH] CWE-434 CVE-2024-54525: A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
nvd
CVE-2021-30835P3HIGHCVSS 7.8fixed in 8.0≥ unspecified, < 82021-10-19
CVE-2021-30835 [HIGH] CVE-2021-30835: This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catal This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2017-2513P3CRITICALCVSS 9.8≤ 3.22017-05-22
CVE-2017-2513 [CRITICAL] CWE-416 CVE-2017-2513: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application cra
nvdapple
Apple watchOS vulnerabilities | cvebase