Apple watchOS vulnerabilities

1,895 known vulnerabilities affecting apple/watchos.

Total CVEs
1,895
CISA KEV
51
actively exploited
Public exploits
123
Exploited in wild
40
Severity breakdown
CRITICAL140HIGH970MEDIUM715LOW68UNKNOWN2

Vulnerabilities

Page 39 of 95
CVE-2022-22600MEDIUMCVSS 5.5fixed in 8.5≥ unspecified, < 8.52022-03-18
CVE-2022-22600 [MEDIUM] CVE-2022-22600: The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.
nvdapple
CVE-2022-22592MEDIUMCVSS 6.5fixed in 8.4≥ unspecified, < 8.42022-03-18
CVE-2022-22592 [MEDIUM] CVE-2022-22592: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvdapple
CVE-2022-22589MEDIUMCVSS 6.1fixed in 8.4≥ unspecified, < 8.42022-03-18
CVE-2022-22589 [MEDIUM] CVE-2022-22589: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 a A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.
nvdapple
CVE-2022-22599LOWCVSS 2.4fixed in 8.5≥ unspecified, < 8.52022-03-18
CVE-2022-22599 [LOW] CVE-2022-22599: Description: A permissions issue was addressed with improved validation. This issue is fixed in watc Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.
nvdapple
CVE-2022-22670LOWCVSS 3.3fixed in 8.5≥ unspecified, < 8.52022-03-18
CVE-2022-22670 [LOW] CVE-2022-22670: An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, i An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.
nvdapple
CVE-2022-22624HIGHCVSS 8.8v8.52022-03-14
CVE-2022-22624 [HIGH] CVE-2022-22624: watchOS 8.5 Apple Security Update: About the security content of watchOS 8.5 Product: watchOS Version: 8.5 CVE: CVE-2022-22624 Component: WebKit Bugzilla 233172
apple
CVE-2022-22662MEDIUMCVSS 6.5v8.52022-03-14
CVE-2022-22662 [MEDIUM] CVE-2022-22662: watchOS 8.5 Apple Security Update: About the security content of watchOS 8.5 Product: watchOS Version: 8.5 CVE: CVE-2022-22662 Component: WebKit Impact: Processing maliciously crafted web content may disclose sensitive user information Description: A cookie management issue was addressed with improved state management.
apple
CVE-2022-26981HIGHCVSS 7.8fixed in 8.72022-03-13
CVE-2022-26981 [HIGH] CWE-120 CVE-2022-26981: Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (cal Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
nvdapple
CVE-2022-23308HIGHCVSS 7.5fixed in 8.62022-02-26
CVE-2022-23308 [HIGH] CWE-416 CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
nvdapple
CVE-2022-21658MEDIUMCVSS 6.3fixed in 8.52022-01-20
CVE-2022-21658 [MEDIUM] CWE-363 CVE-2022-21658: Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick
nvdapple
CVE-2019-8703CRITICALCVSS 9.8fixed in 6.0≥ unspecified, < 62021-12-23
CVE-2019-8703 [CRITICAL] CVE-2019-8703: This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macO This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macOS Catalina 10.15, iOS 13. An application may be able to gain elevated privileges.
nvd
CVE-2017-13905HIGHCVSS 8.1fixed in 4.2≥ unspecified, < 4.22021-12-23
CVE-2017-13905 [HIGH] CWE-362 CVE-2017-13905: A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11. A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.
nvdapple
CVE-2017-13880HIGHCVSS 7.8fixed in 4.2≥ unspecified, < 4.22021-12-23
CVE-2017-13880 [HIGH] CVE-2017-13880: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An application may be able to execute arbitrary code with kernel privilege.
nvdapple
CVE-2018-4302HIGHCVSS 7.8fixed in 4≥ unspecified, < 42021-12-23
CVE-2018-4302 [HIGH] CWE-476 CVE-2018-4302: A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.
nvd
CVE-2021-30767MEDIUMCVSS 5.5≤ 8.3≥ unspecified, < 8.32021-12-23
CVE-2021-30767 [MEDIUM] CVE-2021-30767: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A local user may be able to modify protected parts of the file system.
nvdapple
CVE-2021-31013MEDIUMCVSS 5.5v8.32021-12-13
CVE-2021-31013 [MEDIUM] CVE-2021-31013: watchOS 8.3 Apple Security Update: About the security content of watchOS 8.3 Product: watchOS Version: 8.3 CVE: CVE-2021-31013 Component: FontParser Impact: Processing a maliciously crafted font may result in the disclosure of process memory Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2021-30840HIGHCVSS 7.8fixed in 8.0≥ unspecified, < 82021-10-28
CVE-2021-30840 [HIGH] CVE-2021-30840: This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.
nvd
CVE-2021-30814HIGHCVSS 7.8fixed in 8.0≥ unspecified, < 82021-10-28
CVE-2021-30814 [HIGH] CWE-787 CVE-2021-30814: A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.
nvd
CVE-2021-30818HIGHCVSS 8.8fixed in 8.0≥ unspecified, < 82021-10-28
CVE-2021-30818 [HIGH] CWE-843 CVE-2021-30818: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 a A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30809HIGHCVSS 8.8fixed in 8.0≥ unspecified, < 82021-10-28
CVE-2021-30809 [HIGH] CWE-416 CVE-2021-30809: A use after free issue was addressed with improved memory management. This issue is fixed in Safari A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd