VendorsApplewatchosall versions
Vulnerabilities

Apple WATCHOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1930CVEs
CVE-2020-3891
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. A person with physical access to a locked iOS device may be able to respond to messages even when replies are disabled.
Published 2020-04-01 · Modified
2.4EPSS 0.003
CVE-2022-22599
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.
Published 2022-03-18 · Modified
2.4EPSS 0.003
CVE-2019-8682
The issue was addressed with improved UI handling. This issue is fixed in iOS 12.4, watchOS 5.3. A user may inadvertently complete an in-app purchase while on the lock screen.
Published 2019-12-18 · Modified
2.4EPSS 0.003
CVE-2019-8548
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode may not clear when the device goes to sleep.
Published 2019-12-18 · Modified
2.4EPSS 0.003
CVE-2023-32417
This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 9.5. An attacker with physical access to a locked Apple Watch may be able to view user photos or contacts via accessibility features.
Published 2023-06-23 · Modified
2.4EPSS 0.003
CVE-2024-27814
This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen.
Published 2024-06-10 · Modified
2.4EPSS 0.003
CVE-2026-43679
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.
Published 2026-08-21 · Analyzed
2.4EPSS 0.002
CVE-2015-5863
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
Published 2015-09-18 · Modified
2.1EPSS 0.003
CVE-2015-5842
XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.
Published 2015-09-18 · Modified
2.1EPSS 0.003
CVE-2015-5898
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
Published 2015-09-18 · Modified
2.1EPSS 0.002
← Prev49 / 49