cbcvebase.

Apple watchOS vulnerabilities

2,036 known vulnerabilities affecting apple/watchos.

Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2

Vulnerabilities

Page 95 of 102
CVE-2017-2417P4MEDIUMCVSS 5.5≤ 3.1.32017-04-02
CVE-2017-2417 [MEDIUM] CWE-835 CVE-2017-2417: An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "CoreGraphics" component. It allows remote attackers to cause a denial of service (infinite recursion) via a crafted image.
nvdapple
CVE-2021-30776P4MEDIUMCVSS 5.5fixed in 7.62021-09-08
CVE-2021-30776 [MEDIUM] CVE-2021-30776: A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-004 Catalina. Playing a malicious audio file may lead to an unexpected application termination.
nvd
CVE-2015-5523P4MEDIUMCVSS 4.3≤ 1.0.12015-08-11
CVE-2015-5523 [MEDIUM] CWE-119 CVE-2015-5523: The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial o The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
nvd
CVE-2020-29615P4MEDIUMCVSS 5.5fixed in 7.2≥ unspecified, < 7.22021-04-02
CVE-2020-29615 [MEDIUM] CWE-125 CVE-2020-29615: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7 An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted image may lead to a denial of service.
nvd
CVE-2019-8668P4MEDIUMCVSS 5.5fixed in 5.3≥ unspecified, < 5.32020-10-27
CVE-2019-8668 [MEDIUM] CWE-20 CVE-2019-8668: A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, t A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, tvOS 12.4, watchOS 5.3. Processing a maliciously crafted image may lead to a denial of service.
nvdapple
CVE-2018-4381P4MEDIUMCVSS 5.5v5.12018-10-30
CVE-2018-4381 [MEDIUM] CVE-2018-4381: watchOS 5.1 Apple Security Update: About the security content of watchOS 5.1 Product: watchOS Version: 5.1 CVE: CVE-2018-4381 Component: Mail Impact: Processing a maliciously crafted message may lead to a denial of service Description: A resource exhaustion issue was addressed with improved input validation.
apple
CVE-2025-24124P4MEDIUMCVSS 5.5fixed in 11.32025-01-27
CVE-2025-24124 [MEDIUM] CVE-2025-24124: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected app termination.
nvdapple
CVE-2025-24161P4MEDIUMCVSS 5.5fixed in 11.32025-01-27
CVE-2025-24161 [MEDIUM] CWE-754 CVE-2025-24161: The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadO The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected app termination.
nvdapple
CVE-2024-44185P4MEDIUMCVSS 5.5fixed in 10.62024-10-24
CVE-2024-44185 [MEDIUM] CVE-2024-44185: The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadO The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
nvdapple
CVE-2025-24086P4MEDIUMCVSS 5.5fixed in 11.32025-01-27
CVE-2025-24086 [MEDIUM] CWE-770 CVE-2025-24086: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing an image may lead to a denial-of-service.
nvdapple
CVE-2024-27880P4MEDIUMCVSS 5.5fixed in 11.0fixed in 112024-09-17
CVE-2024-27880 [MEDIUM] CWE-125 CVE-2024-27880: An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, tvOS 18, visionOS 2, watchOS 11. Processing a maliciously crafted file may lead to unexpected app termination.
nvd
CVE-2024-44183P4MEDIUMCVSS 5.5≤ 11.0fixed in 112024-09-17
CVE-2024-44183 [MEDIUM] CWE-400 CVE-2024-44183: A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, tvOS 18, visionOS 2, watchOS 11. An app may be able to cause a denial-of-service.
nvd
CVE-2023-32400P4MEDIUMCVSS 5.5fixed in 9.5≥ unspecified, < 9.52023-06-23
CVE-2023-32400 [MEDIUM] CWE-281 CVE-2023-32400: This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watc This issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
nvdapple
CVE-2025-31226P4MEDIUMCVSS 5.5fixed in 11.52025-05-12
CVE-2025-31226 [MEDIUM] CWE-400 CVE-2025-31226: A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, i A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted image may lead to a denial-of-service.
nvdapple
CVE-2026-28852P4MEDIUMCVSS 5.5fixed in 26.42026-03-25
CVE-2026-28852 [MEDIUM] CWE-20 CVE-2026-28852: A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and A stack overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause a denial-of-service.
nvd
CVE-2023-28185P4MEDIUMCVSS 5.5fixed in 9.4≥ unspecified, < 9.42024-01-10
CVE-2023-28185 [MEDIUM] CWE-190 CVE-2023-28185: An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16. An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4, watchOS 9.4, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. An app may be able to cause a denial-of-service.
nvdapple
CVE-2025-24184P4MEDIUMCVSS 5.5fixed in 11.32025-05-19
CVE-2025-24184 [MEDIUM] CVE-2025-24184: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.
nvdapple
CVE-2026-20654P4MEDIUMCVSS 5.5fixed in 26.32026-02-11
CVE-2026-20654 [MEDIUM] CWE-119 CVE-2026-20654: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
nvdapple
CVE-2026-64724P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-64724 [MEDIUM] CWE-400 CVE-2026-64724: The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be able to cause a denial-of-service.
nvd
CVE-2026-43817P4MEDIUMCVSS 5.5fixed in 26.62026-07-27
CVE-2026-43817 [MEDIUM] CWE-125 CVE-2026-43817: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 a An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
Apple watchOS vulnerabilities | cvebase