cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 50 of 102
CVE-2021-30927P3HIGHCVSS 7.8fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30927 [HIGH] CWE-416 CVE-2021-30927: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2024-55549P3HIGHCVSS 7.8v11.32025-01-27
CVE-2024-55549 [HIGH] CVE-2024-55549: watchOS 11.3 Apple Security Update: About the security content of watchOS 11.3 Product: watchOS Version: 11.3 CVE: CVE-2024-55549 Component: LaunchServices Impact: An app may be able to fingerprint the user Description: This issue was addressed with improved redaction of sensitive information.
apple
CVE-2023-41174P3HIGHCVSS 7.8fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-41174 [HIGH] CVE-2023-41174: The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iP The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2023-38136P3HIGHCVSS 7.8fixed in 9.6≥ unspecified, < 9.62023-07-27
CVE-2023-38136 [HIGH] CVE-2023-38136: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2024-44255P3HIGHCVSS 7.8fixed in 11.12024-10-28
CVE-2024-44255 [HIGH] CWE-22 CVE-2024-44255: A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to run arbitrary shortcuts without user consent.
nvd
CVE-2025-43277P3HIGHCVSS 7.8fixed in 11.62025-07-30
CVE-2025-43277 [HIGH] CWE-119 CVE-2025-43277: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.8, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted audio file may lead to memory corruption.
nvdapple
CVE-2020-27899P3HIGHCVSS 7.8fixed in 7.1≥ unspecified, < 7.12021-04-02
CVE-2020-27899 [HIGH] CWE-416 CVE-2020-27899: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A local attacker may be able to elevate their privileges.
nvd
CVE-2022-32940P3HIGHCVSS 7.8fixed in 9.1≥ unspecified, < 9.12022-11-01
CVE-2022-32940 [HIGH] CWE-119 CVE-2022-32940: The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 16.1 and The issue was addressed with improved bounds checks. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2022-32903P3HIGHCVSS 7.8fixed in 9.0≥ unspecified, < 9+1 more2022-11-01
CVE-2022-32903 [HIGH] CWE-416 CVE-2022-32903: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 16 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2023-32734P3HIGHCVSS 7.8fixed in 9.6≥ unspecified, < 9.62023-07-27
CVE-2023-32734 [HIGH] CVE-2023-32734: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2023-38580P3HIGHCVSS 7.8fixed in 9.6≥ unspecified, < 9.62023-07-27
CVE-2023-38580 [HIGH] CVE-2023-38580: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2024-54522P3HIGHCVSS 7.8fixed in 11.22025-01-27
CVE-2024-54522 [HIGH] CWE-787 CVE-2024-54522: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2024-54517P3HIGHCVSS 7.8fixed in 11.22025-01-27
CVE-2024-54517 [HIGH] CWE-787 CVE-2024-54517: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2021-1849P3HIGHCVSS 7.5fixed in 7.4≥ unspecified, < 7.42021-09-08
CVE-2021-1849 [HIGH] CWE-347 CVE-2021-1849: An issue in code signature validation was addressed with improved checks. This issue is fixed in mac An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.
nvd
CVE-2026-43780P3HIGHCVSS 7.8fixed in 26.62026-07-27
CVE-2026-43780 [HIGH] CWE-190 CVE-2026-43780: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 an An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected app termination.
nvd
CVE-2025-24126P3HIGHCVSS 7.3fixed in 11.32025-01-27
CVE-2025-24126 [HIGH] CWE-400 CVE-2025-24126: An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequ An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to corrupt process memory.
nvd
CVE-2025-43462P3HIGHCVSS 7.5fixed in 26.12025-11-04
CVE-2025-43462 [HIGH] CWE-400 CVE-2025-43462: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2025-43494P3HIGHCVSS 7.5fixed in 26.12025-12-12
CVE-2025-43494 [HIGH] CWE-20 CVE-2025-43494: A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 an A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An attacker may be able to cause a persistent denial-of-service.
nvdapple
CVE-2026-28987P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28987 [HIGH] CWE-532 CVE-2026-28987: A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iP A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to leak sensitive kernel state.
nvd
CVE-2026-28974P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28974 [HIGH] CWE-284 CVE-2026-28974: This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
nvd
Apple watchOS vulnerabilities | cvebase