Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL141HIGH1004MEDIUM758LOW68UNKNOWN65
Vulnerabilities
Page 3 of 102
CVE-2020-9859P1HIGHCVSS 7.8KEVfixed in 6.2.6≥ unspecified, < watchOS 6.2.62020-06-05
CVE-2020-9859 [HIGH] CWE-415 CVE-2020-9859: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 1
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-28204P1MEDIUMCVSS 6.5KEVfixed in 9.5≥ unspecified, < 9.52023-06-23
CVE-2023-28204 [MEDIUM] CWE-125 CVE-2023-28204: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
nvdapple
CVE-2020-9818P1HIGHCVSS 8.8KEVfixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-06-09
CVE-2020-9818 [HIGH] CWE-787 CVE-2020-9818: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.
nvd
CVE-2023-38606P1MEDIUMCVSS 5.5KEVfixed in 9.6≥ unspecified, < 9.62023-07-27
CVE-2023-38606 [MEDIUM] CVE-2023-38606: This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.
This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited again
nvdapple
CVE-2025-43510P1HIGHCVSS 7.8KEVfixed in 26.12025-12-12
CVE-2025-43510 [HIGH] CWE-667 CVE-2025-43510: A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iO
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.
nvdapple
CVE-2018-4344P2HIGHCVSS 7.8KEVfixed in 5.02019-04-03
CVE-2018-4344 [HIGH] CWE-119 CVE-2018-4344: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2021-31010P2HIGHCVSS 7.5KEVfixed in 7.6.2≥ unspecified, < 7.6+2 more2021-08-24
CVE-2021-31010 [HIGH] CWE-502 CVE-2021-31010: A deserialization issue was addressed through improved validation. This issue is fixed in Security U
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the tim
nvdapple
CVE-2021-1879P1MEDIUMCVSS 6.1KEVfixed in 7.3.3≥ unspecified, < 7.32021-04-02
CVE-2021-1879 [MEDIUM] CWE-79 CVE-2021-1879: This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2025-43520P1MEDIUMCVSS 5.5KEVfixed in 26.12025-12-12
CVE-2025-43520 [MEDIUM] CWE-120 CVE-2025-43520: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.
nvdapple
CVE-2025-43200P2MEDIUMCVSS 4.2KEVfixed in 11.3.12025-06-16
CVE-2025-43200 [MEDIUM] CVE-2025-43200: This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4,
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via
nvdapple
CVE-2020-9819P2MEDIUMCVSS 4.3KEVfixed in 5.3.7≥ 6.0.0, < 6.2.5+1 more2020-06-09
CVE-2020-9819 [MEDIUM] CWE-787 CVE-2020-9819: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 1
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.
nvd
CVE-2018-4233P1HIGHCVSS 8.8ExploitedPoCfixed in 4.3.12018-06-08
CVE-2018-4233 [HIGH] CWE-119 CVE-2018-4233: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary
nvdapple
CVE-2022-46689P1HIGHCVSS 7.0ExploitedPoCfixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-46689 [HIGH] CWE-362 CVE-2022-46689: A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS M
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2019-8646P1HIGHCVSS 7.5ExploitedPoCRansomwarefixed in 5.3≥ unspecified, < watchOS 5.32019-12-18
CVE-2019-8646 [HIGH] CWE-125 CVE-2019-8646: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. A remote attacker may be able to leak memory.
nvdapple
CVE-2022-42864P1HIGHCVSS 7.0ExploitedPoCfixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42864 [HIGH] CWE-362 CVE-2022-42864: A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2020-9802P1HIGHCVSS 8.8ExploitedPoCfixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-06-09
CVE-2020-9802 [HIGH] CVE-2020-9802: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2018-4404P1HIGHCVSS 8.8ExploitedPoCv4.3.12018-05-29
CVE-2018-4404 [HIGH] CVE-2018-4404: watchOS 4.3.1
Apple Security Update: About the security content of watchOS 4.3.1
Product: watchOS
Version: 4.3.1
CVE: CVE-2018-4404
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed with improved memory handling.
apple
CVE-2018-4443P1HIGHCVSS 8.8ExploitedPoCfixed in 5.1.22019-04-03
CVE-2018-4443 [HIGH] CWE-119 CVE-2018-4443: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvdapple
CVE-2018-4386P1HIGHCVSS 8.8ExploitedPoCfixed in 5.12019-04-03
CVE-2018-4386 [HIGH] CWE-119 CVE-2018-4386: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2018-4237P2HIGHCVSS 7.8ExploitedPoCfixed in 4.3.12018-06-08
CVE-2018-4237 [HIGH] CVE-2018-4237: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "libxpc" component. It allows attackers to gain privileges via a crafted app that leverages a logic error.
nvdapple