Apple watchOS vulnerabilities
1,895 known vulnerabilities affecting apple/watchos.
Total CVEs
1,895
CISA KEV
51
actively exploited
Public exploits
123
Exploited in wild
40
Severity breakdown
CRITICAL140HIGH970MEDIUM715LOW68UNKNOWN2
Vulnerabilities
Page 67 of 95
CVE-2019-8620HIGHCVSS 7.5fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8620 [HIGH] CWE-200 CVE-2019-8620: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A device may be passively tracked by its WiFi MAC address.
nvdapple
CVE-2019-8747HIGHCVSS 7.8fixed in 6.1≥ unspecified, < watchOS 6.12019-12-18
CVE-2019-8747 [HIGH] CWE-787 CVE-2019-8747: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in watchO
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2019-8676HIGHCVSS 8.8fixed in 5.3≥ unspecified, < watchOS 5.32019-12-18
CVE-2019-8676 [HIGH] CWE-787 CVE-2019-8676: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8684HIGHCVSS 8.8fixed in 5.3≥ unspecified, < watchOS 5.32019-12-18
CVE-2019-8684 [HIGH] CWE-787 CVE-2019-8684: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-8658MEDIUMCVSS 6.1fixed in 5.3≥ unspecified, < watchOS 5.32019-12-18
CVE-2019-8658 [MEDIUM] CWE-79 CVE-2019-8658: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-8626MEDIUMCVSS 6.5fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8626 [MEDIUM] CWE-20 CVE-2019-8626: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvdapple
CVE-2019-8764MEDIUMCVSS 6.1fixed in 6.1≥ unspecified, < watchOS 6.12019-12-18
CVE-2019-8764 [MEDIUM] CWE-79 CVE-2019-8764: A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Proc
A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2019-7293MEDIUMCVSS 5.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-7293 [MEDIUM] CWE-787 CVE-2019-7293: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A local user may be able to read kernel memory.
nvdapple
CVE-2019-6207MEDIUMCVSS 5.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-6207 [MEDIUM] CWE-125 CVE-2019-6207: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-8546MEDIUMCVSS 5.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8546 [MEDIUM] CVE-2019-8546: An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2,
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A local user may be able to view sensitive user information.
nvdapple
CVE-2019-8560MEDIUMCVSS 5.5fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8560 [MEDIUM] CWE-125 CVE-2019-8560: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to read restricted memory.
nvdapple
CVE-2019-8550MEDIUMCVSS 4.3fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8550 [MEDIUM] CWE-459 CVE-2019-8550: An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This
An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the call is ringing.
nvd
CVE-2019-8607MEDIUMCVSS 6.5fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8607 [MEDIUM] CWE-125 CVE-2019-8607: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3,
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may result in the disclosure of process memory.
nvdapple
CVE-2019-8798MEDIUMCVSS 5.5fixed in 6.1≥ unspecified, < watchOS 6.12019-12-18
CVE-2019-8798 [MEDIUM] CWE-787 CVE-2019-8798: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
nvdapple
CVE-2019-8517MEDIUMCVSS 6.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8517 [MEDIUM] CWE-125 CVE-2019-8517: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.2,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted font may result in the disclosure of process memory.
nvdapple
CVE-2019-7292MEDIUMCVSS 6.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-7292 [MEDIUM] CWE-20 CVE-2019-7292: A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, wa
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may result in the disclosure of process memory.
nvdapple
CVE-2019-8540MEDIUMCVSS 5.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8540 [MEDIUM] CWE-665 CVE-2019-8540: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-8598MEDIUMCVSS 5.5fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8598 [MEDIUM] CWE-119 CVE-2019-8598: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A malicious application may be able to read restricted memory.
nvdapple
CVE-2019-8510MEDIUMCVSS 5.5fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8510 [MEDIUM] CWE-125 CVE-2019-8510: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-8794MEDIUMCVSS 5.5fixed in 6.1≥ unspecified, < watchOS 6.12019-12-18
CVE-2019-8794 [MEDIUM] CWE-20 CVE-2019-8794: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
nvdapple