Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 51 of 102
CVE-2026-43655P3HIGHCVSS 7.3fixed in 26.52026-05-11
CVE-2026-43655 [HIGH] CWE-125 CVE-2026-43655: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.
nvd
CVE-2024-9681P3MEDIUMCVSS 6.5v11.42025-04-01
CVE-2024-9681 [MEDIUM] CVE-2024-9681: watchOS 11.4
Apple Security Update: About the security content of watchOS 11.4
Product: watchOS
Version: 11.4
CVE: CVE-2024-9681
Component: CVE-2024-9681
apple
CVE-2026-28972P3MEDIUMCVSS 6.5fixed in 26.52026-05-11
CVE-2026-28972 [MEDIUM] CWE-787 CVE-2026-28972: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2023-42849P3MEDIUMCVSS 6.5fixed in 10.1≥ unspecified, < 10.12023-10-25
CVE-2023-42849 [MEDIUM] CWE-119 CVE-2023-42849: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.
nvdapple
CVE-2019-6230P3HIGHCVSS 8.6fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6230 [HIGH] CWE-665 CVE-2019-6230: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2018-4311P3HIGHCVSS 8.1fixed in 5.02019-04-03
CVE-2018-4311 [HIGH] CWE-200 CVE-2018-4311: The issue was addressed by removing origin information. This issue affected versions prior to iOS 12
The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2021-30955P3HIGHCVSS 7.0fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30955 [HIGH] CWE-362 CVE-2021-30955: A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. A malicious application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2016-4632P3HIGHCVSS 7.5fixed in 2.2.22016-07-22
CVE-2016-4632 [HIGH] CWE-119 CVE-2016-4632: ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2
ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvdapple
CVE-2015-6978P3MEDIUMCVSS 6.8≤ 2.02015-10-23
CVE-2015-6978 [MEDIUM] CVE-2015-6978: FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitr
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, CVE-2015-7010, and CVE-2015-7018.
nvdapple
CVE-2016-1818P3HIGHCVSS 7.8≤ 2.22016-05-20
CVE-2016-1818 [HIGH] CVE-2016-1818: IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b
IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016-1819.
nvdapple
CVE-2018-4100P3HIGHCVSS 7.5fixed in 4.2.22018-04-03
CVE-2018-4100 [HIGH] CWE-400 CVE-2018-4100: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. watchOS before 4.2.2 is affected. The issue involves the "LinkPresentation" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted text message.
nvdapple
CVE-2016-4650P3HIGHCVSS 7.8v2.2.22016-07-18
CVE-2016-4650 [HIGH] CVE-2016-4650: watchOS 2.2.2
Apple Security Update: About the security content of watchOS 2.2.2
Product: watchOS
Version: 2.2.2
CVE: CVE-2016-4650
Component: IOHIDFamily
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
apple
CVE-2018-4343P3HIGHCVSS 7.8fixed in 5.02019-04-03
CVE-2018-4343 [HIGH] CWE-119 CVE-2018-4343: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4126P3HIGHCVSS 7.8fixed in 5.02019-04-03
CVE-2018-4126 [HIGH] CWE-119 CVE-2018-4126: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.
nvd
CVE-2017-2407P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2407 [HIGH] CWE-119 CVE-2017-2407: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvdapple
CVE-2017-2435P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2435 [HIGH] CWE-119 CVE-2017-2435: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf
nvdapple
CVE-2017-2406P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2406 [HIGH] CWE-119 CVE-2017-2406: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvdapple
CVE-2015-5903P3CRITICALCVSS 10.0v1.02015-09-18
CVE-2015-5903 [CRITICAL] CVE-2015-5903: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.
nvd
CVE-2017-2487P3HIGHCVSS 7.8≤ 3.1.32017-04-02
CVE-2017-2487 [HIGH] CWE-119 CVE-2017-2487: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a cr
nvdapple
CVE-2016-1824P3HIGHCVSS 7.8fixed in 2.2.12016-05-20
CVE-2016-1824 [HIGH] CVE-2016-1824: IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.
IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1823.
nvdapple