Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 30 of 102
CVE-2026-64747P3HIGHCVSS 7.8fixed in 26.62026-07-27
CVE-2026-64747 [HIGH] CWE-120 CVE-2026-64747: A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and i
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2025-46285P3HIGHCVSS 7.8fixed in 26.22025-12-12
CVE-2025-46285 [HIGH] CWE-190 CVE-2025-46285: An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 a
An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. An app may be able to gain root privileges.
nvdapple
CVE-2024-40771P3HIGHCVSS 7.8fixed in 10.52025-01-15
CVE-2024-40771 [HIGH] CWE-863 CVE-2024-40771: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2025-31183P3CRITICALCVSS 9.8fixed in 11.42025-03-31
CVE-2025-31183 [CRITICAL] CWE-200 CVE-2025-31183: The issue was addressed with improved restriction of data container access. This issue is fixed in i
The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
nvdapple
CVE-2025-31221P3HIGHCVSS 7.5fixed in 11.52025-05-12
CVE-2025-31221 [HIGH] CWE-190 CVE-2025-31221: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.5 an
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may be able to leak memory.
nvdapple
CVE-2025-43186P3CRITICALCVSS 9.8fixed in 11.62025-07-30
CVE-2025-43186 [CRITICAL] CWE-119 CVE-2025-43186: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Parsing a file may lead to an unexpected app termination.
nvdapple
CVE-2025-43376P3HIGHCVSS 7.5fixed in 26.0fixed in 262025-11-04
CVE-2025-43376 [HIGH] CVE-2025-43376: A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18
A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.
nvdapple
CVE-2019-8531P3CRITICALCVSS 9.8fixed in 5.22020-10-27
CVE-2019-8531 [CRITICAL] CWE-295 CVE-2019-8531: A validation issue existed in Trust Anchor Management. This issue was addressed with improved valida
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. An untrusted radius server certificate may be trusted.
nvdapple
CVE-2026-28883P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28883 [HIGH] CWE-416 CVE-2026-28883: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
nvd
CVE-2026-43658P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-43658 [HIGH] CWE-119 CVE-2026-43658: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvd
CVE-2022-23308P3HIGHCVSS 7.5fixed in 8.62022-02-26
CVE-2022-23308 [HIGH] CWE-416 CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
nvdapple
CVE-2026-43778P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43778 [CRITICAL] CWE-416 CVE-2026-43778: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvd
CVE-2026-64729P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64729 [CRITICAL] CWE-416 CVE-2026-64729: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-64720P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-64720 [CRITICAL] CWE-362 CVE-2026-64720: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPa
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-43814P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-43814 [CRITICAL] CWE-416 CVE-2026-43814: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2026-28928P3CRITICALCVSS 9.8fixed in 26.62026-07-27
CVE-2026-28928 [CRITICAL] CWE-416 CVE-2026-28928: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2018-4262P3HIGHCVSS 8.8fixed in 4.3.22019-01-11
CVE-2018-4262 [HIGH] CWE-119 CVE-2018-4262: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
nvdapple
CVE-2016-8687P3HIGHCVSS 7.5v3.1.32017-01-23
CVE-2016-8687 [HIGH] CVE-2016-8687: watchOS 3.1.3
Apple Security Update: About the security content of watchOS 3.1.3
Product: watchOS
Version: 3.1.3
CVE: CVE-2016-8687
Component: Kernel
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A use after free issue was addressed through improved memory management.
apple
CVE-2020-9868P3CRITICALCVSS 9.1fixed in 6.2.8≥ unspecified, < watchOS 6.2.82020-10-22
CVE-2020-9868 [CRITICAL] CWE-295 CVE-2020-9868: A certificate validation issue existed when processing administrator added certificates. This issue
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An attacker may have been able to impersonate a trusted website using shared key material for an ad
nvdapple
CVE-2024-44206P3CRITICALCVSS 9.3fixed in 10.62024-10-24
CVE-2024-44206 [CRITICAL] CVE-2024-44206: An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in
An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A user may be able to bypass some web content restrictions.
nvdapple