Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 73 of 102
CVE-2023-32420P4HIGHCVSS 7.1fixed in 9.5≥ unspecified, < 9.52023-06-23
CVE-2023-32420 [HIGH] CWE-125 CVE-2023-32420: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to cause unexpected system termination or read kernel memory.
nvdapple
CVE-2023-41988P4MEDIUMCVSS 6.8fixed in 10.1≥ unspecified, < 10.12023-10-25
CVE-2023-41988 [MEDIUM] CWE-200 CVE-2023-41988: This issue was addressed by restricting options offered on a locked device. This issue is fixed in m
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.
nvdapple
CVE-2020-9829P4MEDIUMCVSS 6.5fixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-06-09
CVE-2020-9829 [MEDIUM] CWE-20 CVE-2020-9829: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted text message may lead to application denial of service.
nvd
CVE-2018-4429P4MEDIUMCVSS 6.5fixed in 5.1.22019-04-03
CVE-2018-4429 [MEDIUM] CWE-20 CVE-2018-4429: A spoofing issue existed in the handling of URLs. This issue was addressed with improved input valid
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.1, watchOS 5.1.2.
nvdapple
CVE-2023-23512P4MEDIUMCVSS 6.5fixed in 9.3≥ unspecified, < 9.32023-02-27
CVE-2023-23512 [MEDIUM] CVE-2023-23512: The issue was addressed with improved handling of caches. This issue is fixed in watchOS 9.3, tvOS 1
The issue was addressed with improved handling of caches. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Visiting a website may lead to an app denial-of-service.
nvdapple
CVE-2023-42914P4MEDIUMCVSS 6.3fixed in 10.2≥ unspecified, < 10.22023-12-12
CVE-2023-42914 [MEDIUM] CVE-2023-42914: The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to break out of its sandbox.
nvdapple
CVE-2021-30689P4MEDIUMCVSS 6.1fixed in 7.52021-09-08
CVE-2021-30689 [MEDIUM] CWE-79 CVE-2021-30689: A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14
A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2021-30744P4MEDIUMCVSS 6.1fixed in 7.52021-09-08
CVE-2021-30744 [MEDIUM] CWE-79 CVE-2021-30744: Description: A cross-origin issue with iframe elements was addressed with improved tracking of secur
Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.
nvdapple
CVE-2021-1826P4MEDIUMCVSS 6.1fixed in 7.4≥ unspecified, < 7.42021-09-08
CVE-2021-1826 [MEDIUM] CWE-79 CVE-2021-1826: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, i
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2021-30855P4MEDIUMCVSS 5.5fixed in 8.02021-08-24
CVE-2021-30855 [MEDIUM] CWE-59 CVE-2021-30855: A validation issue existed in the handling of symlinks. This issue was addressed with improved valid
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15, watchOS 8, macOS Big Sur 11.6. An application may be able to access restricted files.
nvd
CVE-2019-15164P4MEDIUMCVSS 5.3v6.1.12019-12-10
CVE-2019-15164 [MEDIUM] CVE-2019-15164: watchOS 6.1.1
Apple Security Update: About the security content of watchOS 6.1.1
Product: watchOS
Version: 6.1.1
CVE: CVE-2019-15164
Component: CVE-2019-15164
apple
CVE-2025-24212P4MEDIUMCVSS 6.3fixed in 11.42025-03-31
CVE-2025-24212 [MEDIUM] CVE-2025-24212: This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPad
This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvdapple
CVE-2025-30429P4MEDIUMCVSS 6.3fixed in 11.42025-03-31
CVE-2025-30429 [MEDIUM] CVE-2025-30429: A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iP
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.
nvdapple
CVE-2019-8753P4MEDIUMCVSS 6.1fixed in 6.0≥ unspecified, < 62020-10-27
CVE-2019-8753 [MEDIUM] CWE-79 CVE-2019-8753: This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15, watchOS 6, iOS 13, tvOS 13. Processing maliciously crafted web content may lead to a cross site scripting attack.
nvd
CVE-2026-28867P4MEDIUMCVSS 6.2fixed in 26.42026-03-25
CVE-2026-28867 [MEDIUM] CVE-2026-28867: This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS
This issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to leak sensitive kernel state.
nvd
CVE-2021-30769P4MEDIUMCVSS 5.5fixed in 7.6≥ unspecified, < 7.62021-09-08
CVE-2021-30769 [MEDIUM] CWE-287 CVE-2021-30769: A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2015-5841P4MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5841 [MEDIUM] CWE-74 CVE-2015-5841: The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header w
The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
nvd
CVE-2024-44296P4MEDIUMCVSS 5.4fixed in 11.12024-10-28
CVE-2024-44296 [MEDIUM] CVE-2024-44296: The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPa
The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2020-10002P4MEDIUMCVSS 5.5fixed in 7.1≥ unspecified, < 7.12020-12-08
CVE-2020-10002 [MEDIUM] CVE-2020-10002: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A local user may be able to read arbitrary files.
nvd
CVE-2023-41968P4MEDIUMCVSS 5.5fixed in 10.0≥ unspecified, < 102023-09-27
CVE-2023-41968 [MEDIUM] CWE-59 CVE-2023-41968: This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.
nvdapple