cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 26 of 102
CVE-2018-4150P3HIGHCVSS 7.8fixed in 4.32018-04-03
CVE-2018-4150 [HIGH] CWE-119 CVE-2018-4150: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app
nvdapple
CVE-2018-4359P3HIGHCVSS 8.8fixed in 5.02019-04-03
CVE-2018-4359 [HIGH] CWE-119 CVE-2018-4359: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2018-4358P3HIGHCVSS 8.8fixed in 5.02019-04-03
CVE-2018-4358 [HIGH] CWE-119 CVE-2018-4358: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2018-4299P3HIGHCVSS 8.8fixed in 5.02019-04-03
CVE-2018-4299 [HIGH] CWE-119 CVE-2018-4299: Multiple memory corruption issues were addressed with improved memory handling. This issue affected Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2018-4361P3HIGHCVSS 8.8fixed in 5.02019-04-03
CVE-2018-4361 [HIGH] CVE-2018-4361: A memory consumption issue was addressed with improved memory handling. This issue affected versions A memory consumption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2021-30925P3CRITICALCVSS 9.1fixed in 8.0≥ unspecified, < 82021-08-24
CVE-2021-30925 [CRITICAL] CWE-863 CVE-2021-30925: The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2026-39868P3CRITICALCVSS 9.1fixed in 26.62026-06-29
CVE-2026-39868 [CRITICAL] CWE-20 CVE-2026-39868: This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadO This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2019-9506P3HIGHCVSS 8.1v5.32019-08-14
CVE-2019-9506 [HIGH] CWE-310 CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encrypti The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
nvdapple
CVE-2022-26757P3HIGHCVSS 7.8fixed in 8.6≥ unspecified, < 8.6+4 more2022-05-26
CVE-2022-26757 [HIGH] CWE-416 CVE-2022-26757: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2021-30847P3HIGHCVSS 7.8fixed in 8.02021-10-19
CVE-2021-30847 [HIGH] CVE-2021-30847: This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2024-0258P3HIGHCVSS 8.6fixed in 10.42024-03-08
CVE-2024-0258 [HIGH] CWE-284 CVE-2024-0258: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
nvdapple
CVE-2024-7264P3MEDIUMCVSS 6.5v26.22025-12-12
CVE-2024-7264 [MEDIUM] CVE-2024-7264: watchOS 26.2 Apple Security Update: About the security content of watchOS 26.2 Product: watchOS Version: 26.2 CVE: CVE-2024-7264 Component: CVE-2024-7264
apple
CVE-2021-1772P3HIGHCVSS 7.8fixed in 7.32021-04-02
CVE-2021-1772 [HIGH] CWE-787 CVE-2021-1772: A stack overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur A stack overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted text file may lead to arbitrary code execution.
nvd
CVE-2020-27916P3HIGHCVSS 7.8fixed in 7.1≥ unspecified, < 7.12020-12-08
CVE-2020-27916 [HIGH] CWE-787 CVE-2020-27916: An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Bi An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.
nvd
CVE-2021-30917P3HIGHCVSS 7.8fixed in 8.12021-08-24
CVE-2021-30917 [HIGH] CWE-20 CVE-2021-30917: A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with i A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted image may le
nvdapple
CVE-2021-30942P3HIGHCVSS 7.8fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30942 [HIGH] CWE-787 CVE-2021-30942: Description: A memory corruption issue in the processing of ICC profiles was addressed with improved Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.
nvdapple
CVE-2022-22584P3HIGHCVSS 7.8fixed in 8.4≥ unspecified, < 8.42022-03-18
CVE-2022-22584 [HIGH] CWE-787 CVE-2022-22584: A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.
nvdapple
CVE-2021-30954P3HIGHCVSS 7.8fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30954 [HIGH] CWE-843 CVE-2021-30954: A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2 A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2021-30928P3HIGHCVSS 7.8fixed in 8.0≥ unspecified, < 82021-08-24
CVE-2021-30928 [HIGH] CWE-787 CVE-2021-30928: A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6, watchOS 8, tvOS 15, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30926P3HIGHCVSS 7.8fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30926 [HIGH] CWE-787 CVE-2021-30926: Description: A memory corruption issue in the processing of ICC profiles was addressed with improved Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. Processing a maliciously crafted image may lead to arbitrary code execution.
nvdapple
Apple watchOS vulnerabilities | cvebase