Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 74 of 102
CVE-2019-8798P4MEDIUMCVSS 5.5fixed in 6.1≥ unspecified, < watchOS 6.12019-12-18
CVE-2019-8798 [MEDIUM] CWE-787 CVE-2019-8798: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.
nvdapple
CVE-2021-1769P4MEDIUMCVSS 5.5fixed in 7.32021-04-02
CVE-2021-1769 [MEDIUM] CVE-2021-1769: A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Sec
A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
nvd
CVE-2025-43444P4MEDIUMCVSS 5.3fixed in 26.12025-11-04
CVE-2025-43444 [MEDIUM] CWE-276 CVE-2025-43444: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 an
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to fingerprint the user.
nvdapple
CVE-2020-9894P4MEDIUMCVSS 4.3fixed in 6.2.8≥ unspecified, < watchOS 6.2.82020-10-16
CVE-2020-9894 [MEDIUM] CWE-125 CVE-2020-9894: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
nvdapple
CVE-2015-8242P4MEDIUMCVSS 5.8≤ 2.12015-12-15
CVE-2015-8242 [MEDIUM] CWE-119 CVE-2015-8242: The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
nvdapple
CVE-2016-4773P4HIGHCVSS 7.1fixed in 3.02016-09-25
CVE-2016-4773 [HIGH] CWE-125 CVE-2016-4773: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4774 and CVE-2016-4776.
nvd
CVE-2016-4776P4HIGHCVSS 7.1fixed in 3.02016-09-25
CVE-2016-4776 [HIGH] CVE-2016-4776: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4774.
nvd
CVE-2016-4774P4HIGHCVSS 7.1fixed in 3.02016-09-25
CVE-2016-4774 [HIGH] CVE-2016-4774: The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows at
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4776.
nvd
CVE-2016-3619P4MEDIUMCVSS 6.5v3.22017-03-27
CVE-2016-3619 [MEDIUM] CVE-2016-3619: watchOS 3.2
Apple Security Update: About the security content of watchOS 3.2
Product: watchOS
Version: 3.2
CVE: CVE-2016-3619
Component: CVE-2016-3619
apple
CVE-2016-1837P4MEDIUMCVSS 5.5fixed in 2.2.12016-05-20
CVE-2016-1837 [MEDIUM] CWE-416 CVE-2016-1837: Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiter
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
nvdapple
CVE-2016-1836P4MEDIUMCVSS 5.5fixed in 2.2.12016-05-20
CVE-2016-1836 [MEDIUM] CWE-416 CVE-2016-1836: Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
nvdapple
CVE-2020-27935P4MEDIUMCVSS 6.3fixed in 7.1≥ unspecified, < 7.12021-04-02
CVE-2020-27935 [MEDIUM] CVE-2020-27935: Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2,
Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
CVE-2022-26766P4MEDIUMCVSS 5.5fixed in 8.6≥ unspecified, < 8.6+4 more2022-05-26
CVE-2022-26766 [MEDIUM] CWE-295 CVE-2022-26766: A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iO
A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.
nvdapple
CVE-2018-4377P4MEDIUMCVSS 6.1fixed in 5.12019-04-03
CVE-2018-4377 [MEDIUM] CWE-79 CVE-2018-4377: A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validatio
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.
nvdapple
CVE-2024-23223P4MEDIUMCVSS 6.2fixed in 10.32024-01-23
CVE-2024-23223 [MEDIUM] CWE-732 CVE-2024-23223: A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and i
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to access sensitive user data.
nvdapple
CVE-2021-1883P4MEDIUMCVSS 5.5fixed in 7.4≥ unspecified, < 7.42021-09-08
CVE-2021-1883 [MEDIUM] CWE-787 CVE-2021-1883: This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojav
This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted server messages may lead to heap corruption.
nvd
CVE-2021-1760P4MEDIUMCVSS 5.5fixed in 7.32021-04-02
CVE-2021-1760 [MEDIUM] CWE-787 CVE-2021-1760: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application could execute arbitrary code leading to compromise of user information.
nvd
CVE-2018-4293P4MEDIUMCVSS 5.3fixed in 4.3.22019-04-03
CVE-2018-4293 [MEDIUM] CWE-20 CVE-2018-4293: A cookie management issue was addressed with improved checks. This issue affected versions prior to
A cookie management issue was addressed with improved checks. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
nvdapple
CVE-2020-9787P4MEDIUMCVSS 5.3fixed in 6.2≥ unspecified, < watchOS 6.22020-10-22
CVE-2020-9787 [MEDIUM] CVE-2020-9787: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. Some websites may not have appeared in Safari Preferences.
nvd
CVE-2023-40408P4MEDIUMCVSS 5.3fixed in 10.1≥ unspecified, < 10.12023-10-25
CVE-2023-40408 [MEDIUM] CWE-400 CVE-2023-40408: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Hide My Email may be deactivated unexpectedly.
nvdapple