Apple watchOS vulnerabilities
2,036 known vulnerabilities affecting apple/watchos.
Total CVEs
2,036
CISA KEV
51
actively exploited
Public exploits
137
Exploited in wild
85
Severity breakdown
CRITICAL160HIGH1024MEDIUM782LOW68UNKNOWN2
Vulnerabilities
Page 98 of 102
CVE-2024-23293P4MEDIUMCVSS 4.6fixed in 10.42024-03-08
CVE-2024-23293 [MEDIUM] CVE-2024-23293: This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.
nvdapple
CVE-2026-28992P4MEDIUMCVSS 4.7fixed in 26.52026-05-11
CVE-2026-28992 [MEDIUM] CWE-362 CVE-2026-28992: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker may be able to cause unexpected app termination.
nvd
CVE-2025-30439P4MEDIUMCVSS 4.6fixed in 11.42025-03-31
CVE-2025-30439 [MEDIUM] CWE-200 CVE-2025-30439: The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.
nvdapple
CVE-2024-40813P4MEDIUMCVSS 4.6fixed in 10.62024-07-29
CVE-2024-40813 [MEDIUM] CWE-922 CVE-2024-40813: A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 an
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
nvdapple
CVE-2020-9993P4MEDIUMCVSS 4.3fixed in 7.0≥ unspecified, < 7.02020-12-08
CVE-2020-9993 [MEDIUM] CWE-1021 CVE-2020-9993: The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0,
The issue was addressed with improved UI handling. This issue is fixed in watchOS 7.0, Safari 14.0, iOS 14.0 and iPadOS 14.0. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2022-22621P4MEDIUMCVSS 4.6fixed in 8.5≥ unspecified, < 8.52022-03-18
CVE-2022-22621 [MEDIUM] CVE-2022-22621: This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS
This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.
nvdapple
CVE-2024-44171P4MEDIUMCVSS 4.6fixed in 11.0fixed in 112024-09-17
CVE-2024-44171 [MEDIUM] CVE-2024-44171: This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPad
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.
nvd
CVE-2019-8550P4MEDIUMCVSS 4.3fixed in 5.2≥ unspecified, < watchOS 5.22019-12-18
CVE-2019-8550 [MEDIUM] CWE-459 CVE-2019-8550: An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This
An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the call is ringing.
nvd
CVE-2021-30810P4MEDIUMCVSS 4.3fixed in 8.0≥ unspecified, < 82021-10-19
CVE-2021-30810 [MEDIUM] CWE-862 CVE-2021-30810: An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 a
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.
nvd
CVE-2022-32857P4MEDIUMCVSS 4.3fixed in 8.7≥ unspecified, < 8.7+1 more2022-08-24
CVE-2022-32857 [MEDIUM] CWE-319 CVE-2022-32857: This issue was addressed by using HTTPS when sending information over the network. This issue is fix
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a user’s activity.
nvdapple
CVE-2025-43374P4MEDIUMCVSS 4.3fixed in 11.52025-11-21
CVE-2025-43374 [MEDIUM] CWE-121 CVE-2025-43374: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 a
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in physical proximity may be able to cause an out-of-bounds read in kernel memory.
nvdapple
CVE-2025-43265P4MEDIUMCVSS 4.0fixed in 11.62025-07-30
CVE-2025-43265 [MEDIUM] CWE-125 CVE-2025-43265: An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.
nvdapple
CVE-2015-8035P4LOWCVSS 2.6≤ 2.12015-11-18
CVE-2015-8035 [LOW] CWE-399 CVE-2015-8035: The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, whic
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
nvdapple
CVE-2017-7003P4MEDIUMCVSS 5.5fixed in 3.2.22018-04-03
CVE-2017-7003 [MEDIUM] CWE-20 CVE-2017-7003: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted file.
nvdapple
CVE-2016-7615P4MEDIUMCVSS 5.5≤ 2.2.22017-02-20
CVE-2016-7615 [MEDIUM] CVE-2016-7615: An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component, which allows local users to cause a denial of service via unspecified vectors.
nvdapple
CVE-2026-43743P4MEDIUMCVSS 4.7fixed in 26.62026-06-29
CVE-2026-43743 [MEDIUM] CWE-362 CVE-2026-43743: A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and i
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
nvd
CVE-2023-32391P4MEDIUMCVSS 4.6fixed in 9.5≥ unspecified, < 9.52023-06-23
CVE-2023-32391 [MEDIUM] CWE-125 CVE-2023-32391: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, w
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. A shortcut may be able to use sensitive data with certain actions without prompting the user.
nvdapple
CVE-2015-6997P4MEDIUMCVSS 4.3≤ 2.02015-10-23
CVE-2015-6997 [MEDIUM] CWE-254 CVE-2015-6997: The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecR
The X.509 certificate-trust implementation in Apple iOS before 9.1 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoints by leveraging access to a revoked certificate.
nvdapple
CVE-2022-22654P4MEDIUMCVSS 4.3fixed in 8.5≥ unspecified, < 8.52022-03-18
CVE-2022-22654 [MEDIUM] CVE-2022-22654: A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a ma
A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may lead to address bar spoofing.
nvdapple
CVE-2026-20609P4MEDIUMCVSS 4.4fixed in 26.32026-02-11
CVE-2026-20609 [MEDIUM] CWE-125 CVE-2026-20609: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
nvdapple