Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 72 of 102
CVE-2019-8664P4MEDIUMCVSS 6.5fixed in 5.2.1≥ unspecified, < 5.22020-10-27
CVE-2019-8664 [MEDIUM] CWE-20 CVE-2019-8664: An input validation issue was addressed with improved input validation. This issue is fixed in iOS 1
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. Processing a maliciously crafted message may lead to a denial of service.
nvdapple
CVE-2021-1821P4MEDIUMCVSS 6.5fixed in 7.62021-10-28
CVE-2021-1821 [MEDIUM] CVE-2021-1821: A logic issue was addressed with improved state management. This issue is fixed in watchOS 7.6, macO
A logic issue was addressed with improved state management. This issue is fixed in watchOS 7.6, macOS Big Sur 11.5. Visiting a maliciously crafted webpage may lead to a system denial of service.
nvd
CVE-2024-54658P4MEDIUMCVSS 6.5fixed in 10.42025-02-10
CVE-2024-54658 [MEDIUM] CWE-400 CVE-2024-54658: The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2022-42799P4MEDIUMCVSS 6.1fixed in 9.1≥ unspecified, < 9.12022-11-01
CVE-2022-42799 [MEDIUM] CWE-1021 CVE-2022-42799: The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 1
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
nvdapple
CVE-2021-1884P4MEDIUMCVSS 5.9fixed in 7.4≥ unspecified, < 7.42021-09-08
CVE-2021-1884 [MEDIUM] CWE-362 CVE-2021-1884: A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-00
A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to cause a denial of service.
nvd
CVE-2019-15165P4MEDIUMCVSS 5.3v6.1.12019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvdapple
CVE-2025-43448P4MEDIUMCVSS 6.3fixed in 26.12025-11-04
CVE-2025-43448 [MEDIUM] CWE-59 CVE-2025-43448: This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to break out of its sandbox.
nvdapple
CVE-2019-15161P4MEDIUMCVSS 5.3v6.1.12019-12-10
CVE-2019-15161 [MEDIUM] CVE-2019-15161: watchOS 6.1.1
Apple Security Update: About the security content of watchOS 6.1.1
Product: watchOS
Version: 6.1.1
CVE: CVE-2019-15161
Component: CVE-2019-15161
apple
CVE-2024-27840P4MEDIUMCVSS 6.3fixed in 10.52024-06-10
CVE-2024-27840 [MEDIUM] CWE-786 CVE-2024-27840: The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.
nvdapple
CVE-2023-32445P4MEDIUMCVSS 6.1fixed in 9.6≥ unspecified, < 9.62023-07-28
CVE-2023-32445 [MEDIUM] CWE-79 CVE-2023-32445: This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS
This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. Processing a document may lead to a cross site scripting attack.
nvdapple
CVE-2017-13080P4MEDIUMCVSS 5.3v4.12017-10-31
CVE-2017-13080 [MEDIUM] CVE-2017-13080: watchOS 4.1
Apple Security Update: About the security content of watchOS 4.1
Product: watchOS
Version: 4.1
CVE: CVE-2017-13080
Component: Wi-Fi
Impact: An attacker in Wi-Fi range may force nonce reuse in WPA multicast/GTK clients (Key Reinstallation Attacks - KRACK)
Description: A logic issue existed in the handling of state transitions. This was addressed with improved state management.
apple
CVE-2021-30720P4MEDIUMCVSS 5.4fixed in 7.52021-09-08
CVE-2021-30720 [MEDIUM] CWE-287 CVE-2021-30720: A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 a
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.
nvdapple
CVE-2025-31241P4MEDIUMCVSS 5.3fixed in 11.52025-05-12
CVE-2025-31241 [MEDIUM] CWE-415 CVE-2025-31241: A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 a
A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remote attacker may cause an unexpected app termination.
nvdapple
CVE-2021-30710P4HIGHCVSS 7.1fixed in 7.52021-09-08
CVE-2021-30710 [HIGH] CWE-787 CVE-2021-30710: A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may cause a denial of service or potentially disclose memory contents.
nvdapple
CVE-2017-7151P4HIGHCVSS 7.0fixed in 4.22019-04-03
CVE-2017-7151 [HIGH] CWE-362 CVE-2017-7151: A race condition was addressed with additional validation. This issue affected versions prior to iOS
A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.
nvdapple
CVE-2016-1811P4MEDIUMCVSS 6.5fixed in 2.2.12016-05-20
CVE-2016-1811 [MEDIUM] CWE-476 CVE-2016-1811: ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1
ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
nvdapple
CVE-2015-8317P4MEDIUMCVSS 5.0v2.2.22016-07-18
CVE-2015-8317 [MEDIUM] CVE-2015-8317: watchOS 2.2.2
Apple Security Update: About the security content of watchOS 2.2.2
Product: watchOS
Version: 2.2.2
CVE: CVE-2015-8317
Component: Libc
Impact: A remote attacker may be able to cause unexpected application termination or arbitrary code execution
Description: A buffer overflow existed within the "link_ntoa()" function in linkaddr.c. This issue was addressed through additional bounds checking.
apple
CVE-2015-5896P4HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5896 [HIGH] CVE-2015-5896: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5903.
nvd
CVE-2015-5868P4HIGHCVSS 7.2v1.02015-09-18
CVE-2015-5868 [HIGH] CWE-119 CVE-2015-5868: The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5896 and CVE-2015-5903.
nvd
CVE-2019-8576P4HIGHCVSS 7.1fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8576 [HIGH] CWE-125 CVE-2019-8576: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A local user may be able to cause unexpected system termination or read kernel memory.
nvdapple