Apple watchOS vulnerabilities

1,895 known vulnerabilities affecting apple/watchos.

Total CVEs
1,895
CISA KEV
51
actively exploited
Public exploits
123
Exploited in wild
40
Severity breakdown
CRITICAL140HIGH970MEDIUM715LOW68UNKNOWN2

Vulnerabilities

Page 73 of 95
CVE-2018-4304MEDIUMCVSS 5.0fixed in 5.02019-04-03
CVE-2018-4304 [MEDIUM] CWE-20 CVE-2018-4304: A denial of service issue was addressed with improved validation. This issue affected versions prior A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2018-4313MEDIUMCVSS 5.5fixed in 5.02019-04-03
CVE-2018-4313 [MEDIUM] CWE-20 CVE-2018-4313: A consistency issue existed in the handling of application snapshots. The issue was addressed with i A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of message deletions. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvd
CVE-2018-4305MEDIUMCVSS 6.5fixed in 5.02019-04-03
CVE-2018-4305 [MEDIUM] CWE-20 CVE-2018-4305: An input validation issue was addressed with improved input validation. This issue affected versions An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvd
CVE-2019-5608CRITICALCVSS 9.8v5.22019-03-27
CVE-2019-5608 [CRITICAL] CVE-2019-5608: watchOS 5.2 Apple Security Update: About the security content of watchOS 5.2 Product: watchOS Version: 5.2 CVE: CVE-2019-5608 Component: Kernel Impact: A remote attacker may be able to alter network traffic data Description: A memory corruption issue existed in the handling of IPv6 packets. This issue was addressed with improved memory management.
apple
CVE-2019-7286HIGHCVSS 7.8KEVPoCv5.22019-03-27
CVE-2019-7286 [HIGH] CVE-2019-7286: watchOS 5.2 Apple Security Update: About the security content of watchOS 5.2 Product: watchOS Version: 5.2 CVE: CVE-2019-7286 Component: Foundation Impact: An application may be able to gain elevated privileges Description: A memory corruption issue was addressed with improved input validation.
apple
CVE-2019-6215HIGHCVSS 8.8PoCfixed in 5.1.32019-03-05
CVE-2019-6215 [HIGH] CWE-843 CVE-2019-6215: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1. A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2019-6230HIGHCVSS 8.6fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6230 [HIGH] CWE-665 CVE-2019-6230: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2019-6224HIGHCVSS 8.8PoCfixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6224 [HIGH] CWE-119 CVE-2019-6224: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A remote attacker may be able to initiate a FaceTime call causing arbitrary code execution.
nvdapple
CVE-2019-6217HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6217 [HIGH] CWE-787 CVE-2019-6217: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6213HIGHCVSS 7.8PoCfixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6213 [HIGH] CWE-119 CVE-2019-6213: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, ma A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2019-6226HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6226 [HIGH] CWE-787 CVE-2019-6226: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6214HIGHCVSS 8.6PoCfixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6214 [HIGH] CWE-843 CVE-2019-6214: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1. A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
nvdapple
CVE-2019-6216HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6216 [HIGH] CWE-787 CVE-2019-6216: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6227HIGHCVSS 8.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6227 [HIGH] CWE-787 CVE-2019-6227: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12 A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
nvdapple
CVE-2019-6202HIGHCVSS 7.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6202 [HIGH] CWE-125 CVE-2019-6202: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. A malicious application may be able to elevate privileges.
nvdapple
CVE-2019-6219HIGHCVSS 7.5fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6219 [HIGH] CWE-20 CVE-2019-6219: A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. Processing a maliciously crafted message may lead to a denial of service.
nvdapple
CVE-2019-6210HIGHCVSS 7.8fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6210 [HIGH] CWE-787 CVE-2019-6210: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to execute arbitrary code with kernel privileges.
nvdapple
CVE-2019-6231MEDIUMCVSS 5.5fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6231 [MEDIUM] CWE-125 CVE-2019-6231: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.
nvdapple
CVE-2019-6209MEDIUMCVSS 5.5PoCfixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6209 [MEDIUM] CWE-125 CVE-2019-6209: An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to determine kernel memory layout.
nvdapple
CVE-2019-6235CRITICALCVSS 10.0≥ unspecified, < watchOS 5.1.32019-03-04
CVE-2019-6235 [CRITICAL] CWE-787 CVE-2019-6235: A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.
nvdapple