Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 75 of 102
CVE-2015-5860P4MEDIUMCVSS 5.0v1.02015-09-18
CVE-2015-5860 [MEDIUM] CWE-200 CVE-2015-5860: The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remot
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.
nvd
CVE-2023-42888P4MEDIUMCVSS 5.5fixed in 10.2≥ unspecified, < 10.22024-01-23
CVE-2023-42888 [MEDIUM] CWE-200 CVE-2023-42888: The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, w
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.
nvdapple
CVE-2021-1807P4MEDIUMCVSS 5.5fixed in 7.4≥ unspecified, < 7.42021-09-08
CVE-2021-1807 [MEDIUM] CWE-20 CVE-2021-1807: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 14.5 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4. A local user may be able to write arbitrary files.
nvd
CVE-2024-54500P4MEDIUMCVSS 5.5fixed in 11.22024-12-12
CVE-2024-54500 [MEDIUM] CVE-2024-54500: The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted image may result in disclosure of process memory.
nvd
CVE-2024-40835P4MEDIUMCVSS 5.5fixed in 10.62024-07-29
CVE-2024-40835 [MEDIUM] CVE-2024-40835: A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.
nvdapple
CVE-2024-40793P4MEDIUMCVSS 5.5fixed in 10.62024-07-29
CVE-2024-40793 [MEDIUM] CWE-200 CVE-2024-40793: This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPad
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An app may be able to access user-sensitive data.
nvdapple
CVE-2021-1797P4MEDIUMCVSS 5.5fixed in 7.32021-04-02
CVE-2021-1797 [MEDIUM] CVE-2021-1797: The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2,
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to read arbitrary files.
nvd
CVE-2022-32928P4MEDIUMCVSS 5.3fixed in 9.0≥ unspecified, < 92022-11-01
CVE-2022-32928 [MEDIUM] CWE-287 CVE-2022-32928: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.
nvd
CVE-2026-43796P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43796 [MEDIUM] CWE-200 CVE-2026-43796: This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 2
This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-43704P4MEDIUMCVSS 5.3fixed in 26.62026-06-29
CVE-2026-43704 [MEDIUM] CWE-416 CVE-2026-43704: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash.
nvd
CVE-2024-44212P4MEDIUMCVSS 5.3fixed in 11.12024-12-12
CVE-2024-44212 [MEDIUM] CWE-346 CVE-2024-44212: A cookie management issue was addressed with improved state management. This issue is fixed in Safar
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.
nvd
CVE-2017-2450P4HIGHCVSS 7.1≤ 3.1.32017-04-02
CVE-2017-2450 [HIGH] CWE-125 CVE-2017-2450: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via
nvdapple
CVE-2017-2439P4HIGHCVSS 7.1≤ 3.1.32017-04-02
CVE-2017-2439 [HIGH] CWE-125 CVE-2017-2439: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "FontParser" component. It allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) v
nvdapple
CVE-2025-24097P4MEDIUMCVSS 5.0fixed in 11.42025-03-31
CVE-2025-24097 [MEDIUM] CWE-125 CVE-2025-24097: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to read arbitrary file metadata.
nvdapple
CVE-2015-7500P4MEDIUMCVSS 5.0≤ 2.12015-12-15
CVE-2015-7500 [MEDIUM] CWE-119 CVE-2015-7500: The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
nvdapple
CVE-2016-7627P4MEDIUMCVSS 6.5≤ 2.2.22017-02-20
CVE-2016-7627 [MEDIUM] CWE-476 CVE-2016-7627: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreGraphics" component. It allows attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted font.
nvdapple
CVE-2018-4305P4MEDIUMCVSS 6.5fixed in 5.02019-04-03
CVE-2018-4305 [MEDIUM] CWE-20 CVE-2018-4305: An input validation issue was addressed with improved input validation. This issue affected versions
An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
nvd
CVE-2021-30866P4MEDIUMCVSS 6.5fixed in 8.0≥ unspecified, < 82021-08-24
CVE-2021-30866 [MEDIUM] CVE-2021-30866: A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvO
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A device may be passively tracked by its WiFi MAC address.
nvd
CVE-2025-24251P4MEDIUMCVSS 6.5fixed in 11.42025-04-29
CVE-2025-24251 [MEDIUM] CWE-476 CVE-2025-24251: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadO
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may cause an unexpected app termination.
nvdapple
CVE-2025-31203P4MEDIUMCVSS 6.5fixed in 11.42025-04-29
CVE-2025-31203 [MEDIUM] CWE-190 CVE-2025-31203: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 an
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may be able to cause a denial-of-service.
nvdapple