Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL141HIGH1004MEDIUM758LOW68UNKNOWN65
Vulnerabilities
Page 7 of 102
CVE-2014-8147P3HIGHCVSS 7.5PoC≤ 1.0.12015-05-25
CVE-2014-8147 [HIGH] CWE-189 CVE-2014-8147: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implemen
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly
nvd
CVE-2018-4442P2HIGHCVSS 8.8PoCfixed in 5.1.22019-04-03
CVE-2018-4442 [HIGH] CWE-119 CVE-2018-4442: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvdapple
CVE-2018-4438P2HIGHCVSS 8.8PoCfixed in 5.1.22019-04-03
CVE-2018-4438 [HIGH] CWE-119 CVE-2018-4438: A logic issue existed resulting in memory corruption. This was addressed with improved state managem
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
nvdapple
CVE-2018-4382P2HIGHCVSS 8.8PoCfixed in 5.12019-04-03
CVE-2018-4382 [HIGH] CWE-119 CVE-2018-4382: Multiple memory corruption issues were addressed with improved memory handling. This issue affected
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2017-13861P3HIGHCVSS 7.8PoCfixed in 4.22017-12-25
CVE-2017-13861 [HIGH] CWE-119 CVE-2017-13861: An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2015-7112P3CRITICALCVSS 9.3PoC≤ 2.02015-12-11
CVE-2015-7112 [CRITICAL] CVE-2015-7112: The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS befor
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7111.
nvdapple
CVE-2019-8624P3HIGHCVSS 7.5PoCfixed in 5.3≥ unspecified, < watchOS 5.32019-12-18
CVE-2019-8624 [HIGH] CWE-125 CVE-2019-8624: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory.
nvdapple
CVE-2017-2370P3HIGHCVSS 7.8PoCfixed in 3.1.32017-02-20
CVE-2017-2370 [HIGH] CWE-119 CVE-2017-2370: An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted
nvdapple
CVE-2018-4241P3HIGHCVSS 7.8PoCfixed in 4.3.12018-06-08
CVE-2018-4241 [HIGH] CWE-119 CVE-2018-4241: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Kernel" component. A buffer overflow in mptcp_usr_connectx allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2017-13876P3HIGHCVSS 7.8PoCfixed in 4.22017-12-25
CVE-2017-13876 [HIGH] CWE-119 CVE-2017-13876: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted a
nvdapple
CVE-2017-13867P3HIGHCVSS 7.8PoCfixed in 4.22017-12-25
CVE-2017-13867 [HIGH] CWE-119 CVE-2017-13867: An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted a
nvdapple
CVE-2018-4206P3HIGHCVSS 7.8PoCfixed in 4.3.12018-06-08
CVE-2018-4206 [HIGH] CWE-119 CVE-2018-4206: An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Crash Reporter" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via
nvdapple
CVE-2018-4087P3HIGHCVSS 7.8PoCfixed in 4.2.22018-04-03
CVE-2018-4087 [HIGH] CWE-119 CVE-2018-4087: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "Core Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2015-7039P3MEDIUMCVSS 6.8PoC≤ 2.02015-12-11
CVE-2015-7039 [MEDIUM] CVE-2015-7039: Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS b
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7038.
nvdapple
CVE-2022-42867P2HIGHCVSS 8.8fixed in 9.2≥ unspecified, < 9.2+1 more2022-12-15
CVE-2022-42867 [HIGH] CWE-416 CVE-2022-42867: A use after free issue was addressed with improved memory management. This issue is fixed in Safari
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2016-7644P3HIGHCVSS 7.8PoC≤ 2.2.22017-02-20
CVE-2016-7644 [HIGH] CWE-416 CVE-2016-7644: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
nvdapple
CVE-2016-1823P3HIGHCVSS 7.8PoCfixed in 2.2.12016-05-20
CVE-2016-1823 [HIGH] CWE-125 CVE-2016-1823: The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read and memory corruption) via a crafted IOHIDReportType enum, which triggers an incorrect cast, a differ
nvdapple
CVE-2019-6214P3HIGHCVSS 8.6PoCfixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6214 [HIGH] CWE-843 CVE-2019-6214: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2017-2483P3HIGHCVSS 7.8PoC≤ 3.1.32017-04-02
CVE-2017-2483 [HIGH] CWE-119 CVE-2017-2483: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2019-6213P3HIGHCVSS 7.8PoCfixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvdapple