Apple watchOS vulnerabilities

1,895 known vulnerabilities affecting apple/watchos.

Total CVEs
1,895
CISA KEV
51
actively exploited
Public exploits
123
Exploited in wild
40
Severity breakdown
CRITICAL140HIGH970MEDIUM715LOW68UNKNOWN2

Vulnerabilities

Page 25 of 95
CVE-2023-41070MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-41070 [MEDIUM] CVE-2023-41070: A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6, iOS 16. A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive data logged when a user shares a link.
nvdapple
CVE-2023-41073MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-41073 [MEDIUM] CVE-2023-41073: An authorization issue was addressed with improved state management. This issue is fixed in macOS Ve An authorization issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access protected user data.
nvdapple
CVE-2023-40420MEDIUMCVSS 6.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40420 [MEDIUM] CVE-2023-40420: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2023-40399MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40399 [MEDIUM] CVE-2023-40399: The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iP The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to disclose kernel memory.
nvdapple
CVE-2023-40429MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40429 [MEDIUM] CVE-2023-40429: A permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 a A permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access sensitive user data.
nvdapple
CVE-2023-41981MEDIUMCVSS 4.4fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-41981 [MEDIUM] CVE-2023-41981: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvdapple
CVE-2023-40403MEDIUMCVSS 6.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40403 [MEDIUM] CVE-2023-40403: The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tv The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.
nvdapple
CVE-2023-40410MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40410 [MEDIUM] CWE-125 CVE-2023-40410: An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ven An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to disclose kernel memory.
nvdapple
CVE-2023-41968MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-41968 [MEDIUM] CWE-59 CVE-2023-41968: This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.
nvdapple
CVE-2023-38596MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-38596 [MEDIUM] CVE-2023-38596: The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 17 The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may fail to enforce App Transport Security.
nvdapple
CVE-2023-40418MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40418 [MEDIUM] CVE-2023-40418: An authentication issue was addressed with improved state management. This issue is fixed in watchOS An authentication issue was addressed with improved state management. This issue is fixed in watchOS 10. An Apple Watch Ultra may not lock when using the Depth app.
nvdapple
CVE-2023-40424MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40424 [MEDIUM] CVE-2023-40424: The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 1 The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access user-sensitive data.
nvdapple
CVE-2023-40417MEDIUMCVSS 5.4fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40417 [MEDIUM] CVE-2023-40417: A window management issue was addressed with improved state management. This issue is fixed in Safar A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2023-40395LOWCVSS 3.3fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40395 [LOW] CVE-2023-40395: The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 a The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access contacts.
nvdapple
CVE-2023-40520LOWCVSS 3.3fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40520 [LOW] CVE-2023-40520: The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to access edited photos saved to a temporary directory.
nvdapple
CVE-2023-40456LOWCVSS 3.3fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40456 [LOW] CVE-2023-40456: The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to access edited photos saved to a temporary directory.
nvdapple
CVE-2023-41065LOWCVSS 3.3fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-41065 [LOW] CVE-2023-41065: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to read sensitive location information.
nvdapple
CVE-2023-40427LOWCVSS 3.3fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40427 [LOW] CVE-2023-40427: The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6, The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read sensitive location information.
nvdapple
CVE-2023-35990LOWCVSS 3.3fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-35990 [LOW] CWE-863 CVE-2023-35990: The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 1 The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14. An app may be able to identify what other apps a user has installed.
nvdapple
CVE-2023-41992HIGHCVSS 7.8KEVv10.0.12023-09-21
CVE-2023-41992 [HIGH] CVE-2023-41992: watchOS 10.0.1 Apple Security Update: About the security content of watchOS 10.0.1 Product: watchOS Version: 10.0.1 CVE: CVE-2023-41992 Component: Kernel Impact: A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. Description: The issue was addressed with improved checks.
apple