cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 58 of 102
CVE-2019-6202P3HIGHCVSS 7.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6202 [HIGH] CWE-125 CVE-2019-6202: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. A malicious application may be able to elevate privileges.
nvdapple
CVE-2019-8552P3HIGHCVSS 7.8fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8552 [HIGH] CWE-665 CVE-2019-8552: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to elevate privileges.
nvdapple
CVE-2018-4394P3HIGHCVSS 7.8fixed in 5.12019-04-03
CVE-2018-4394 [HIGH] CWE-119 CVE-2018-4394: A memory corruption issue was addressed with improved input validation. This issue affected versions A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1, iTunes 12.9.1.
nvdapple
CVE-2019-8665P3HIGHCVSS 7.5fixed in 5.3≥ unspecified, < watchOS 5.32019-12-18
CVE-2019-8665 [HIGH] CWE-20 CVE-2019-8665: A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, w A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, watchOS 5.3. A remote attacker may cause an unexpected application termination.
nvdapple
CVE-2015-5942P3MEDIUMCVSS 6.8≤ 2.0.02015-10-23
CVE-2015-5942 [MEDIUM] CVE-2015-5942: FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote atta FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5927.
nvdapple
CVE-2025-27113P3LOWCVSS 2.9v11.42025-04-01
CVE-2025-27113 [LOW] CVE-2025-27113: watchOS 11.4 Apple Security Update: About the security content of watchOS 11.4 Product: watchOS Version: 11.4 CVE: CVE-2025-27113 Component: CVE-2025-27113
apple
CVE-2015-5927P3MEDIUMCVSS 6.8≤ 2.0.02015-10-23
CVE-2015-5927 [MEDIUM] CWE-119 CVE-2015-5927: FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote atta FontParser in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-5942.
nvdapple
CVE-2015-5829P3MEDIUMCVSS 6.8v1.02015-09-18
CVE-2015-5829 [MEDIUM] CWE-119 CVE-2015-5829: Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cau Data Detectors Engine in Apple iOS before 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file.
nvd
CVE-2016-4653P3HIGHCVSS 7.8fixed in 2.2.22016-07-22
CVE-2016-4653 [HIGH] CVE-2016-4653: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2 The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4582.
nvdapple
CVE-2019-8633P3HIGHCVSS 7.5fixed in 5.32020-10-27
CVE-2019-8633 [HIGH] CWE-20 CVE-2019-8633: A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Moja A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, tvOS 12.3, watchOS 5.3. An application may be able to read restricted memory.
nvdapple
CVE-2016-4582P3HIGHCVSS 7.8fixed in 2.2.22016-07-22
CVE-2016-4582 [HIGH] CVE-2016-4582: The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2 The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4653.
nvdapple
CVE-2016-1832P3HIGHCVSS 7.8fixed in 2.2.12016-05-20
CVE-2016-1832 [HIGH] CWE-119 CVE-2016-1832: libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 all libc in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2022-22618P3HIGHCVSS 7.8fixed in 8.5≥ unspecified, < 8.52022-03-18
CVE-2022-22618 [HIGH] CVE-2022-22618: This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and iPad This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. A user may be able to bypass the Emergency SOS passcode prompt.
nvdapple
CVE-2016-4775P3HIGHCVSS 7.8fixed in 3.02016-09-25
CVE-2016-4775 [HIGH] CWE-119 CVE-2016-4775: The kernel in Apple OS X before 10.12, tvOS before 10, and watchOS before 3 allows local users to ga The kernel in Apple OS X before 10.12, tvOS before 10, and watchOS before 3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-1722P3HIGHCVSS 7.8fixed in 2.22016-02-01
CVE-2016-1722 [HIGH] CWE-119 CVE-2016-1722: syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to g syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2023-32425P3HIGHCVSS 7.8fixed in 9.5≥ unspecified, < 9.52023-09-06
CVE-2023-32425 [HIGH] CVE-2023-32425: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16 The issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to gain elevated privileges.
nvdapple
CVE-2018-4436P3HIGHCVSS 7.5fixed in 5.1.22019-04-03
CVE-2018-4436 [HIGH] CWE-295 CVE-2018-4436: A certificate validation issue existed in configuration profiles. This was addressed with additional A certificate validation issue existed in configuration profiles. This was addressed with additional checks. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2.
nvdapple
CVE-2024-54551P3HIGHCVSS 7.5fixed in 10.62025-03-21
CVE-2024-54551 [HIGH] CWE-119 CVE-2024-54551: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2026-28991P3HIGHCVSS 7.5fixed in 26.52026-05-11
CVE-2026-28991 [HIGH] CWE-125 CVE-2026-28991: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.
nvd
CVE-2016-4483P3HIGHCVSS 7.5v2.2.22016-07-18
CVE-2016-4483 [HIGH] CVE-2016-4483: watchOS 2.2.2 Apple Security Update: About the security content of watchOS 2.2.2 Product: watchOS Version: 2.2.2 CVE: CVE-2016-4483 Component: Libc Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple
Apple watchOS vulnerabilities | cvebase