Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 84 of 102
CVE-2020-9944P4MEDIUMCVSS 5.5fixed in 7.0≥ unspecified, < 7.02020-12-08
CVE-2020-9944 [MEDIUM] CWE-125 CVE-2020-9944: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to read restricted memory.
nvdapple
CVE-2018-4413P4MEDIUMCVSS 5.5fixed in 5.12019-04-03
CVE-2018-4413 [MEDIUM] CWE-119 CVE-2018-4413: A memory initialization issue was addressed with improved memory handling. This issue affected versi
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.
nvdapple
CVE-2016-4719P4MEDIUMCVSS 5.5≤ 2.22016-09-18
CVE-2016-4719 [MEDIUM] CWE-200 CVE-2016-4719: The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict acc
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.
nvd
CVE-2018-4399P4MEDIUMCVSS 5.5fixed in 5.02019-04-03
CVE-2018-4399 [MEDIUM] CWE-20 CVE-2018-4399: An access issue existed with privileged API calls. This issue was addressed with additional restrict
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2019-8794P4MEDIUMCVSS 5.5fixed in 6.1≥ unspecified, < watchOS 6.12019-12-18
CVE-2019-8794 [MEDIUM] CWE-20 CVE-2019-8794: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 a
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
nvdapple
CVE-2021-30946P4MEDIUMCVSS 5.5fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30946 [MEDIUM] CVE-2021-30946: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1,
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, macOS Big Sur 11.6.2. A malicious application may be able to bypass certain Privacy preferences.
nvdapple
CVE-2021-30685P4MEDIUMCVSS 5.5fixed in 7.52021-09-08
CVE-2021-30685 [MEDIUM] CVE-2021-30685: This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS
This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Parsing a maliciously crafted audio file may lead to disclosure of user information.
nvdapple
CVE-2021-31007P4MEDIUMCVSS 5.5fixed in 8.1≥ unspecified, < 8.1+3 more2021-08-24
CVE-2021-31007 [MEDIUM] CWE-276 CVE-2021-31007: Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS
Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1, macOS Big Sur 11.6.2, watchOS 8.1, macOS Monterey 12.1. A malicious application may be able to bypass Privacy preferences.
nvdapple
CVE-2020-9809P4MEDIUMCVSS 5.5fixed in 6.2.5≥ unspecified, < watchOS 6.2.52020-06-09
CVE-2020-9809 [MEDIUM] CVE-2020-9809: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine kernel memory layout.
nvd
CVE-2021-30964P4MEDIUMCVSS 5.5fixed in 8.3≥ unspecified, < 8.32021-08-24
CVE-2021-30964 [MEDIUM] CWE-732 CVE-2021-30964: An inherited permissions issue was addressed with additional restrictions. This issue is fixed in ma
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2. A malicious application may be able to bypass Privacy preferences.
nvdapple
CVE-2021-31006P4MEDIUMCVSS 5.5fixed in 7.6≥ unspecified, < 7.62021-08-24
CVE-2021-31006 [MEDIUM] CWE-276 CVE-2021-31006: Description: A permissions issue was addressed with improved validation. This issue is fixed in watc
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 7.6, tvOS 14.7, macOS Big Sur 11.5. A malicious application may be able to bypass certain Privacy preferences.
nvd
CVE-2020-3875P4MEDIUMCVSS 5.5fixed in 6.1.2≥ unspecified, < watchOS 6.1.22020-02-27
CVE-2020-3875 [MEDIUM] CWE-125 CVE-2020-3875: A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.
nvd
CVE-2020-27946P4MEDIUMCVSS 5.5fixed in 7.2≥ unspecified, < 7.22021-04-02
CVE-2020-27946 [MEDIUM] CVE-2020-27946: An information disclosure issue was addressed with improved state management. This issue is fixed in
An information disclosure issue was addressed with improved state management. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font may result in the disclosure of process memory.
nvd
CVE-2022-32817P4MEDIUMCVSS 5.5fixed in 8.7≥ unspecified, < 8.7+1 more2022-09-23
CVE-2022-32817 [MEDIUM] CWE-125 CVE-2022-32817: An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watc
An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.
nvdapple
CVE-2018-4431P4MEDIUMCVSS 5.5fixed in 5.1.22019-04-03
CVE-2018-4431 [MEDIUM] CWE-200 CVE-2018-4431: A memory initialization issue was addressed with improved memory handling. This issue affected versi
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvdapple
CVE-2019-8532P4MEDIUMCVSS 5.5fixed in 5.2≥ unspecified, < 5.22020-10-27
CVE-2019-8532 [MEDIUM] CVE-2019-8532: A permissions issue was addressed by removing vulnerable code and adding additional checks. This iss
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in watchOS 5.2, iOS 12.2. A malicious application may be able to access restricted files.
nvdapple
CVE-2020-29639P4MEDIUMCVSS 5.5v7.02020-09-16
CVE-2020-29639 [MEDIUM] CVE-2020-29639: watchOS 7.0
Apple Security Update: About the security content of watchOS 7.0
Product: watchOS
Version: 7.0
CVE: CVE-2020-29639
Component: FontParser
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: An out-of-bounds read was addressed with improved bounds checking.
apple
CVE-2020-13631P4MEDIUMCVSS 5.5fixed in 7.02020-05-27
CVE-2020-13631 [MEDIUM] CVE-2020-13631: SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, r
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
nvdapple
CVE-2022-26745P4MEDIUMCVSS 5.5v8.62022-05-16
CVE-2022-26745 [MEDIUM] CVE-2022-26745: watchOS 8.6
Apple Security Update: About the security content of watchOS 8.6
Product: watchOS
Version: 8.6
CVE: CVE-2022-26745
Component: Wi-Fi
Impact: A malicious application may disclose restricted memory
Description: A memory corruption issue was addressed with improved validation.
apple
CVE-2018-4235P4MEDIUMCVSS 5.5fixed in 4.3.12018-06-08
CVE-2018-4235 [MEDIUM] CWE-74 CVE-2018-4235: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows local users to perform impersonation attacks via an unspecified injection.
nvdapple