cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 83 of 102
CVE-2026-64721P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64721 [MEDIUM] CWE-664 CVE-2026-64721: This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPad This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.
nvd
CVE-2026-64709P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64709 [MEDIUM] CWE-200 CVE-2026-64709: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.
nvd
CVE-2026-43714P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43714 [MEDIUM] CWE-20 CVE-2026-43714: The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. A malicious app may be able to access protected user data.
nvd
CVE-2026-64741P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64741 [MEDIUM] CWE-200 CVE-2026-64741: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.
nvd
CVE-2026-28988P4MEDIUMCVSS 5.5fixed in 26.52026-05-11
CVE-2026-28988 [MEDIUM] CWE-284 CVE-2026-28988: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An app may be able to bypass certain Privacy preferences.
nvd
CVE-2026-28996P4MEDIUMCVSS 5.5fixed in 26.52026-05-11
CVE-2026-28996 [MEDIUM] CWE-362 CVE-2026-28996: A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadO A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data.
nvd
CVE-2024-54518P4MEDIUMCVSS 5.3fixed in 11.22025-01-27
CVE-2024-54518 [MEDIUM] CWE-125 CVE-2024-54518: The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
nvd
CVE-2015-5837P4MEDIUMCVSS 4.3v1.02015-09-18
CVE-2015-5837 [MEDIUM] CWE-20 CVE-2015-5837: PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and ins PluginKit in Apple iOS before 9 allows attackers to bypass an intended app-trust requirement and install arbitrary extensions via a crafted enterprise app.
nvd
CVE-2025-43434P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43434 [MEDIUM] CWE-416 CVE-2025-43434: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2025-43438P4MEDIUMCVSS 4.3fixed in 26.12025-11-04
CVE-2025-43438 [MEDIUM] CWE-416 CVE-2025-43438: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.
nvdapple
CVE-2020-9946P4MEDIUMCVSS 6.8fixed in 7.0≥ unspecified, < watchOS 7.02020-10-16
CVE-2020-9946 [MEDIUM] CWE-667 CVE-2020-9946: This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watc This issue was addressed with improved checks. This issue is fixed in iOS 14.0 and iPadOS 14.0, watchOS 7.0. The screen lock may not engage after the specified time period.
nvdapple
CVE-2016-1833P4MEDIUMCVSS 5.5fixed in 2.2.12016-05-20
CVE-2016-1833 [MEDIUM] CWE-125 CVE-2016-1833: The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvdapple
CVE-2025-43211P4MEDIUMCVSS 6.2fixed in 11.62025-07-30
CVE-2025-43211 [MEDIUM] CWE-770 CVE-2025-43211: The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing web content may lead to a denial-of-service.
nvdapple
CVE-2026-28822P4MEDIUMCVSS 6.2fixed in 26.42026-03-25
CVE-2026-28822 [MEDIUM] CWE-843 CVE-2026-28822: A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able to cause unexpected app termination.
nvd
CVE-2026-20637P4MEDIUMCVSS 6.2fixed in 26.32026-03-25
CVE-2026-20637 [MEDIUM] CWE-416 CVE-2026-20637: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
nvdapple
CVE-2018-4290P4MEDIUMCVSS 5.9fixed in 4.3.22019-04-03
CVE-2018-4290 [MEDIUM] CVE-2018-4290: A denial of service issue was addressed with improved memory handling. This issue affected versions A denial of service issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, watchOS 4.3.2.
nvdapple
CVE-2020-11764P4MEDIUMCVSS 5.5fixed in 6.2.82020-04-14
CVE-2020-11764 [MEDIUM] CWE-787 CVE-2020-11764: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuf An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
nvdapple
CVE-2019-6231P4MEDIUMCVSS 5.5fixed in 5.1.3≥ unspecified, < watchOS 5.1.32019-03-05
CVE-2019-6231 [MEDIUM] CWE-125 CVE-2019-6231: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.
nvdapple
CVE-2018-4104P4MEDIUMCVSS 5.5fixed in 4.32018-04-03
CVE-2018-4104 [MEDIUM] CWE-200 CVE-2018-4104: An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.
nvdapple
CVE-2021-30768P4MEDIUMCVSS 5.5fixed in 7.62021-09-08
CVE-2021-30768 [MEDIUM] CVE-2021-30768: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. A sandboxed process may be able to circumvent sandbox restrictions.
nvd
Apple watchOS vulnerabilities | cvebase