Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 56 of 102
CVE-2023-32396P3HIGHCVSS 7.8fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-32396 [HIGH] CVE-2023-32396: This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10,
This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges.
nvdapple
CVE-2016-1717P3HIGHCVSS 7.8fixed in 2.22016-02-01
CVE-2016-1717 [HIGH] CWE-119 CVE-2016-1717: The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allo
The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2017-7080P3HIGHCVSS 7.5≤ 3.2.32017-10-23
CVE-2017-7080 [HIGH] CWE-295 CVE-2017-7080: An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended certificate-trust restrictions via a revoked X.509 certificate.
nvd
CVE-2025-31208P3HIGHCVSS 7.5fixed in 11.52025-05-12
CVE-2025-31208 [HIGH] CWE-20 CVE-2025-31208: The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to an unexpected app termination.
nvdapple
CVE-2025-24173P3HIGHCVSS 7.8fixed in 11.42025-03-31
CVE-2025-24173 [HIGH] CWE-284 CVE-2025-24173: This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPa
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvdapple
CVE-2015-7054P3MEDIUMCVSS 6.8≤ 2.02015-12-11
CVE-2015-7054 [MEDIUM] CWE-19 CVE-2015-7054: zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and
zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not initialize memory for an unspecified data structure, which allows remote attackers to execute arbitrary code via a crafted web site.
nvdapple
CVE-2024-44225P3HIGHCVSS 7.8fixed in 11.22024-12-12
CVE-2024-44225 [HIGH] CVE-2024-44225: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, i
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to gain elevated privileges.
nvd
CVE-2023-40419P3HIGHCVSS 7.8fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-40419 [HIGH] CVE-2023-40419: The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17,
The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to gain elevated privileges.
nvdapple
CVE-2022-46712P3HIGHCVSS 7.8v9.12022-10-24
CVE-2022-46712 [HIGH] CVE-2022-46712: watchOS 9.1
Apple Security Update: About the security content of watchOS 9.1
Product: watchOS
Version: 9.1
CVE: CVE-2022-46712
Component: Kernel
Impact: An app may be able to cause unexpected system termination or potentially execute code with kernel privileges
Description: A use after free issue was addressed with improved memory management.
apple
CVE-2021-1787P3HIGHCVSS 7.8fixed in 7.32021-04-02
CVE-2021-1787 [HIGH] CWE-269 CVE-2021-1787: Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Secur
Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges.
nvd
CVE-2022-42849P3HIGHCVSS 7.8fixed in 9.2≥ unspecified, < 9.22022-12-15
CVE-2022-42849 [HIGH] CWE-269 CVE-2022-42849: An access issue existed with privileged API calls. This issue was addressed with additional restrict
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.
nvdapple
CVE-2022-32826P3HIGHCVSS 7.8fixed in 8.7≥ unspecified, < 8.7+1 more2022-09-23
CVE-2022-32826 [HIGH] CWE-269 CVE-2022-32826: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.
nvdapple
CVE-2021-30882P3HIGHCVSS 7.5fixed in 8.0≥ unspecified, < 82021-08-24
CVE-2021-30882 [HIGH] CVE-2021-30882: A logic issue was addressed with improved validation. This issue is fixed in watchOS 8, iOS 15 and i
A logic issue was addressed with improved validation. This issue is fixed in watchOS 8, iOS 15 and iPadOS 15. An application with microphone permission may unexpectedly access microphone input during a FaceTime call.
nvd
CVE-2025-31219P3HIGHCVSS 7.1fixed in 11.52025-05-12
CVE-2025-31219 [HIGH] CWE-119 CVE-2025-31219: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
nvdapple
CVE-2016-5131P3HIGHCVSS 8.8fixed in 3.02016-07-23
CVE-2016-5131 [HIGH] CWE-416 CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82,
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
nvd
CVE-2024-54486P3MEDIUMCVSS 6.5fixed in 11.22024-12-12
CVE-2024-54486 [MEDIUM] CVE-2024-54486: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2019-15163P3HIGHCVSS 7.5v6.1.12019-12-10
CVE-2019-15163 [HIGH] CVE-2019-15163: watchOS 6.1.1
Apple Security Update: About the security content of watchOS 6.1.1
Product: watchOS
Version: 6.1.1
CVE: CVE-2019-15163
Component: CVE-2019-15163
apple
CVE-2022-32816P3MEDIUMCVSS 6.5fixed in 8.7≥ unspecified, < 8.7+1 more2022-09-23
CVE-2022-32816 [MEDIUM] CWE-451 CVE-2022-32816: The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iO
The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.
nvdapple
CVE-2025-30432P3MEDIUMCVSS 6.4fixed in 11.42025-03-31
CVE-2025-30432 [MEDIUM] CWE-287 CVE-2025-30432: A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPad
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.
nvdapple
CVE-2025-31209P3MEDIUMCVSS 6.3fixed in 11.52025-05-12
CVE-2025-31209 [MEDIUM] CWE-125 CVE-2025-31209: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to disclosure of user information.
nvdapple