Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL141HIGH1004MEDIUM758LOW68UNKNOWN65
Vulnerabilities
Page 9 of 102
CVE-2016-1755P3HIGHCVSS 7.8PoCfixed in 2.22016-03-24
CVE-2016-1755 [HIGH] CVE-2016-1755: The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 all
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.
nvdapple
CVE-2016-1813P3HIGHCVSS 7.8PoCfixed in 2.2.12016-05-20
CVE-2016-1813 [HIGH] CWE-476 CVE-2016-1813: The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
nvdapple
CVE-2019-8514P3HIGHCVSS 7.8PoCfixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8514 [HIGH] CVE-2019-8514: A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS M
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. An application may be able to gain elevated privileges.
nvdapple
CVE-2018-4384P3HIGHCVSS 7.8PoCfixed in 5.12019-04-03
CVE-2018-4384 [HIGH] CWE-119 CVE-2018-4384: A memory corruption issue was addressed with improved input validation. This issue affected versions
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, watchOS 5.1.
nvdapple
CVE-2019-8600P2CRITICALCVSS 9.8fixed in 5.2.1≥ unspecified, < watchOS 5.2.12019-12-18
CVE-2019-8600 [CRITICAL] CWE-89 CVE-2019-8600: A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.
nvdapple
CVE-2019-8718P3HIGHCVSS 7.8PoCfixed in 6.0≥ unspecified, < 62020-10-27
CVE-2019-8718 [HIGH] CWE-787 CVE-2019-8718: A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchO
A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6, iOS 13, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
nvd
CVE-2018-4435P3HIGHCVSS 7.8PoCfixed in 5.1.22019-04-03
CVE-2018-4435 [HIGH] CWE-20 CVE-2018-4435: A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.
nvdapple
CVE-2017-2478P3HIGHCVSS 7.0PoC≤ 3.1.32017-04-02
CVE-2017-2478 [HIGH] CWE-362 CVE-2017-2478: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2016-1719P3HIGHCVSS 7.8PoC≤ 2.12016-02-01
CVE-2016-1719 [HIGH] CWE-119 CVE-2016-1719: The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows loc
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2015-6996P3MEDIUMCVSS 6.8PoC≤ 2.0.02015-10-23
CVE-2015-6996 [MEDIUM] CWE-119 CVE-2015-6996: IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows at
IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.
nvdapple
CVE-2015-7068P3HIGHCVSS 7.8PoCfixed in 2.12015-12-11
CVE-2015-7068 [HIGH] CWE-476 CVE-2015-7068: IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 all
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.
nvdapple
CVE-2018-4240P3MEDIUMCVSS 6.5PoCfixed in 4.3.12018-06-08
CVE-2018-4240 [MEDIUM] CWE-20 CVE-2018-4240: An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows remote attackers to cause a denial of service via a crafted message.
nvdapple
CVE-2022-37434P2CRITICALCVSS 9.8fixed in 9.12022-08-05
CVE-2022-37434 [CRITICAL] CWE-787 CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
nvdapple
CVE-2017-2456P3HIGHCVSS 7.0PoC≤ 3.1.32017-04-02
CVE-2017-2456 [HIGH] CWE-362 CVE-2017-2456: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2017-2501P3HIGHCVSS 7.0PoCfixed in 3.2.22017-05-22
CVE-2017-2501 [HIGH] CWE-362 CVE-2017-2501: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
nvdapple
CVE-2018-4280P3HIGHCVSS 7.8PoCfixed in 4.3.22019-04-03
CVE-2018-4280 [HIGH] CWE-119 CVE-2018-4280: A memory corruption issue was addressed with improved memory handling. This issue affected versions
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.
nvdapple
CVE-2016-7621P3HIGHCVSS 7.8PoC≤ 2.2.22017-02-20
CVE-2016-7621 [HIGH] CWE-416 CVE-2016-7621: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via unspecified vectors.
nvdapple
CVE-2018-4407P2HIGHCVSS 8.8fixed in 5.02019-04-03
CVE-2018-4407 [HIGH] CWE-119 CVE-2018-4407: A memory corruption issue was addressed with improved validation. This issue affected versions prior
A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
nvd
CVE-2016-1720P3HIGHCVSS 7.8PoCfixed in 2.22016-02-01
CVE-2016-1720 [HIGH] CWE-119 CVE-2016-1720: IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to ga
IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple
CVE-2016-1721P3HIGHCVSS 7.8PoCfixed in 2.22016-02-01
CVE-2016-1721 [HIGH] CWE-119 CVE-2016-1721: The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.
nvdapple