Apple watchOS vulnerabilities
1,895 known vulnerabilities affecting apple/watchos.
Total CVEs
1,895
CISA KEV
51
actively exploited
Public exploits
123
Exploited in wild
40
Severity breakdown
CRITICAL140HIGH970MEDIUM715LOW68UNKNOWN2
Vulnerabilities
Page 32 of 95
CVE-2022-42864HIGHCVSS 7.0fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42864 [HIGH] CWE-362 CVE-2022-42864: A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2022-46693HIGHCVSS 7.8fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-46693 [HIGH] CWE-787 CVE-2022-46693: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tv
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.
nvdapple
CVE-2022-46700HIGHCVSS 8.8fixed in 9.2≥ unspecified, < 9.2+1 more2022-12-15
CVE-2022-46700 [HIGH] CWE-787 CVE-2022-46700: A memory corruption issue was addressed with improved input validation. This issue is fixed in Safar
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-42849HIGHCVSS 7.8fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42849 [HIGH] CWE-269 CVE-2022-42849: An access issue existed with privileged API calls. This issue was addressed with additional restrict
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
nvdapple
CVE-2022-46691HIGHCVSS 8.8fixed in 9.2≥ unspecified, < 9.2+1 more2022-12-15
CVE-2022-46691 [HIGH] CWE-787 CVE-2022-46691: A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safar
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2022-46692MEDIUMCVSS 5.5fixed in 9.2≥ unspecified, < 9.2+1 more2022-12-15
CVE-2022-46692 [MEDIUM] CWE-345 CVE-2022-46692: A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.
nvdapple
CVE-2022-42866MEDIUMCVSS 5.5fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42866 [MEDIUM] CWE-200 CVE-2022-42866: The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.
nvdapple
CVE-2022-46695MEDIUMCVSS 6.5fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-46695 [MEDIUM] CWE-1021 CVE-2022-46695: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2022-42843MEDIUMCVSS 5.5fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42843 [MEDIUM] CWE-200 CVE-2022-42843: This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 1
This issue was addressed with improved data protection. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. A user may be able to view sensitive user information.
nvdapple
CVE-2022-42859MEDIUMCVSS 5.5fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42859 [MEDIUM] CWE-284 CVE-2022-42859: Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and
Multiple issues were addressed by removing the vulnerable code. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2. An app may be able to bypass Privacy preferences.
nvdapple
CVE-2022-42865MEDIUMCVSS 5.5fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42865 [MEDIUM] CWE-284 CVE-2022-42865: This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16
This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
nvdapple
CVE-2022-46698MEDIUMCVSS 6.5fixed in 9.2≥ unspecified, < 9.2+1 more2022-12-15
CVE-2022-46698 [MEDIUM] CWE-693 CVE-2022-46698: A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCl
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may disclose sensitive user information.
nvdapple
CVE-2022-42852MEDIUMCVSS 6.5fixed in 9.2≥ unspecified, < 9.2+1 more2022-12-15
CVE-2022-42852 [MEDIUM] CWE-200 CVE-2022-42852: The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may result in the disclosure of process memory.
nvdapple
CVE-2022-42855HIGHCVSS 7.1v9.22022-12-13
CVE-2022-42855 [HIGH] CVE-2022-42855: watchOS 9.2
Apple Security Update: About the security content of watchOS 9.2
Product: watchOS
Version: 9.2
CVE: CVE-2022-42855
Component: Preferences
Impact: An app may be able to use arbitrary entitlements
Description: A logic issue was addressed with improved state management.
apple
CVE-2022-46703MEDIUMCVSS 5.5v9.22022-12-13
CVE-2022-46703 [MEDIUM] CVE-2022-46703: watchOS 9.2
Apple Security Update: About the security content of watchOS 9.2
Product: watchOS
Version: 9.2
CVE: CVE-2022-46703
Component: Weather
Impact: An app may be able to read sensitive location information
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2022-46717LOWCVSS 2.4v9.22022-12-13
CVE-2022-46717 [LOW] CVE-2022-46717: watchOS 9.2
Apple Security Update: About the security content of watchOS 9.2
Product: watchOS
Version: 9.2
CVE: CVE-2022-46717
Component: Accessibility
Impact: A user with physical access to a locked Apple Watch may be able to view user photos via accessibility features
Description: A logic issue was addressed with improved restrictions.
apple
CVE-2022-40304HIGHCVSS 7.8fixed in 9.22022-11-23
CVE-2022-40304 [HIGH] CWE-415 CVE-2022-40304: An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
nvdapple
CVE-2022-40303HIGHCVSS 7.5fixed in 9.22022-11-23
CVE-2022-40303 [HIGH] CWE-190 CVE-2022-40303: An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with th
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
nvdapple
CVE-2022-42808CRITICALCVSS 9.8fixed in 9.1≥ unspecified, < 9.12022-11-01
CVE-2022-42808 [CRITICAL] CWE-787 CVE-2022-42808: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvO
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.
nvdapple
CVE-2022-42813CRITICALCVSS 9.8fixed in 9.1≥ unspecified, < 9.12022-11-01
CVE-2022-42813 [CRITICAL] CWE-295 CVE-2022-42813: A certificate validation issue existed in the handling of WKWebView. This issue was addressed with i
A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.
nvdapple