Watch OS Apple Watch OS Apple Watch Operating System

Do you want an email whenever new security vulnerabilities are reported in Apple Watch OS?

Recent Apple Watch OS Security Advisories

Advisory Title Published
HT213340 watchOS 8.7 Security Content July 20, 2022
HT213253 watchOS 8.6 Security Content May 16, 2022
HT213193 watchOS 8.5 Security Content March 14, 2022
HT213059 watchOS 8.4 Security Content January 26, 2022
HT212975 watchOS 8.3 Security Content December 13, 2021
HT212874 watchOS 8.1 Security Content October 25, 2021
HT212819 watchOS 8 Security Content September 20, 2021
HT212806 watchOS 7.6.2 Security Content September 13, 2021
HT212713 watchOS 7.6.1 Security Content July 29, 2021
HT212605 watchOS 7.6 Security Content July 19, 2021

By the Year

In 2022 there have been 71 vulnerabilities in Apple Watch OS with an average score of 7.3 out of ten. Last year Watch OS had 251 security vulnerabilities published. Right now, Watch OS is on track to have less security vulnerabilities in 2022 than it did last year. However, the average CVE base score of the vulnerabilities in 2022 is greater by 0.13.

Year Vulnerabilities Average Score
2022 71 7.32
2021 251 7.19
2020 171 7.37
2019 201 7.70
2018 56 7.54

It may take a day or so for new Watch OS vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple Watch OS Security Vulnerabilities

A buffer overflow issue was addressed with improved memory handling

CVE-2022-22629 8.8 - High - September 23, 2022

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A type confusion issue was addressed with improved state handling

CVE-2022-32814 7.8 - High - September 23, 2022

A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

Object Type Confusion

A use after free issue was addressed with improved memory management

CVE-2022-22628 8.8 - High - September 23, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A logic issue was addressed with improved state management

CVE-2022-22637 8.8 - High - September 23, 2022

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior.

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-32787 8.8 - High - September 23, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A memory corruption issue was addressed with improved state management

CVE-2022-22610 8.8 - High - September 23, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to code execution.

A memory corruption issue was addressed with improved state management

CVE-2022-26700 8.8 - High - September 23, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to code execution.

This issue was addressed with improved checks

CVE-2022-32790 7.5 - High - September 23, 2022

This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Big Sur 11.6.6, Security Update 2022-004 Catalina. A remote user may be able to cause a denial-of-service.

An out-of-bounds write issue was addressed with improved input validation

CVE-2022-32792 8.8 - High - September 23, 2022

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

The issue was addressed with improved memory handling

CVE-2022-32815 7.8 - High - September 23, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved UI handling

CVE-2022-32816 6.5 - Medium - September 23, 2022

The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may lead to UI spoofing.

An out-of-bounds read issue was addressed with improved bounds checking

CVE-2022-32817 5.5 - Medium - September 23, 2022

An out-of-bounds read issue was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2022-32819 7.8 - High - September 23, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.

An out-of-bounds write issue was addressed with improved input validation

CVE-2022-32820 7.8 - High - September 23, 2022

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges.

Memory Corruption

An authorization issue was addressed with improved state management

CVE-2022-32826 7.8 - High - September 23, 2022

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges.

A memory corruption issue was addressed with improved validation

CVE-2022-32821 7.8 - High - September 23, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

A memory initialization issue was addressed with improved memory handling

CVE-2022-32823 5.5 - Medium - September 23, 2022

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to leak sensitive user information.

Improper Initialization

The issue was addressed with improved memory handling

CVE-2022-32825 5.5 - Medium - September 23, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5. An app may be able to disclose kernel memory.

This issue was addressed with improved checks

CVE-2022-32845 10 - Critical - September 23, 2022

This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.

This issue was addressed with improved checks

CVE-2022-32847 9.1 - Critical - September 23, 2022

This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

The issue was addressed with improved memory handling

CVE-2022-32832 6.7 - Medium - September 23, 2022

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved memory handling

CVE-2022-32841 5.5 - Medium - September 23, 2022

The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted image may result in disclosure of process memory.

An out-of-bounds read was addressed with improved input validation

CVE-2020-36521 7.1 - High - September 23, 2022

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.

Out-of-bounds Read

A buffer overflow was addressed with improved bounds checking

CVE-2022-32788 9.8 - Critical - September 20, 2022

A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.

Classic Buffer Overflow

This issue was addressed by using HTTPS when sending information over the network

CVE-2022-32857 4.3 - Medium - August 24, 2022

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a users activity.

The issue was addressed with improved memory handling

CVE-2022-32813 7.8 - High - August 24, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. An app with root privileges may be able to execute arbitrary code with kernel privileges.

The issue was addressed with improved bounds checks

CVE-2022-32839 9.8 - Critical - August 24, 2022

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code execution.

This issue was addressed with improved checks

CVE-2022-32840 7.8 - High - August 24, 2022

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.

Multiple out-of-bounds write issues were addressed with improved bounds checking

CVE-2022-32793 7.5 - High - August 24, 2022

Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to disclose kernel memory.

Memory Corruption

The issue was addressed with improved memory handling

CVE-2022-32810 7.8 - High - August 24, 2022

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.

A use after free issue was addressed with improved memory management

CVE-2022-26757 7.8 - High - May 26, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

An out-of-bounds access issue was addressed with improved bounds checking

CVE-2022-26763 7.8 - High - May 26, 2022

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious application may be able to execute arbitrary code with system privileges.

Buffer Overflow

A memory corruption issue was addressed with improved validation

CVE-2022-26764 4.7 - Medium - May 26, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

Memory Corruption

A race condition was addressed with improved state handling

CVE-2022-26765 4.7 - Medium - May 26, 2022

A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

Race Condition

A certificate parsing issue was addressed with improved checks

CVE-2022-26766 5.5 - Medium - May 26, 2022

A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be able to bypass signature validation.

Improper Certificate Validation

A memory corruption issue was addressed with improved state management

CVE-2022-26768 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4, watchOS 8.6, tvOS 15.5, macOS Big Sur 11.6.6. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A memory corruption issue was addressed with improved state management

CVE-2022-26771 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. A malicious application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-26702 7.8 - High - May 26, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

An access issue was addressed with additional sandbox restrictions on third-party applications

CVE-2022-26706 5.5 - Medium - May 26, 2022

An access issue was addressed with additional sandbox restrictions on third-party applications. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions.

An integer overflow issue was addressed with improved input validation

CVE-2022-26711 9.8 - Critical - May 26, 2022

An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

Integer Overflow or Wraparound

A memory corruption issue was addressed with improved validation

CVE-2022-26714 7.8 - High - May 26, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

This issue was addressed with improved checks

CVE-2022-26726 6.5 - Medium - May 26, 2022

This issue was addressed with improved checks. This issue is fixed in Security Update 2022-004 Catalina, watchOS 8.6, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to capture a user's screen.

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22675 7.8 - High - May 26, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

Memory Corruption

A logic issue was addressed with improved state management

CVE-2022-22632 9.8 - Critical - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, watchOS 8.5, macOS Monterey 12.3. A malicious application may be able to elevate privileges.

The issue was addressed with improved permissions logic

CVE-2022-22600 5.5 - Medium - March 18, 2022

The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.

An access issue was addressed with improved access restrictions

CVE-2022-22670 3.3 - Low - March 18, 2022

An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.

The issue was addressed with additional permissions checks

CVE-2022-22609 7.5 - High - March 18, 2022

The issue was addressed with additional permissions checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to read other applications' settings.

A memory corruption issue was addressed with improved validation

CVE-2022-22666 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. Processing a maliciously crafted image may lead to heap corruption.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-22614 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22613 7.8 - High - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A memory consumption issue was addressed with improved memory handling

CVE-2022-22612 7.8 - High - March 18, 2022

A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.

Buffer Overflow

An out-of-bounds read was addressed with improved input validation

CVE-2022-22611 7.8 - High - March 18, 2022

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to arbitrary code execution.

Out-of-bounds Read

A user interface issue was addressed

CVE-2022-22654 4.3 - Medium - March 18, 2022

A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may lead to address bar spoofing.

Improper Input Validation

A memory corruption issue was addressed with improved validation

CVE-2022-22640 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. An application may be able to execute arbitrary code with kernel privileges.

Buffer Overflow

A null pointer dereference was addressed with improved validation

CVE-2022-22638 6.5 - Medium - March 18, 2022

A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a denial of service attack.

NULL Pointer Dereference

This issue was addressed with improved checks

CVE-2022-22621 4.6 - Medium - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.

Information Disclosure

A use after free issue was addressed with improved memory management

CVE-2022-22615 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

A logic issue was addressed with improved state management

CVE-2022-22592 6.5 - Medium - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

A use after free issue was addressed with improved memory management

CVE-2022-22590 8.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

An out-of-bounds write was addressed with improved input validation

CVE-2021-30771 7.8 - High - March 18, 2022

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6, watchOS 7.5, tvOS 14.6. Processing a maliciously crafted font file may lead to arbitrary code execution.

Memory Corruption

A memory corruption issue was addressed with improved state management

CVE-2022-22633 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.

Memory Corruption

A buffer overflow issue was addressed with improved memory handling

CVE-2022-22593 7.8 - High - March 18, 2022

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be able to execute arbitrary code with kernel privileges.

Classic Buffer Overflow

This issue was addressed with improved checks

CVE-2022-22618 7.8 - High - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. A user may be able to bypass the Emergency SOS passcode prompt.

AuthZ

Description: A permissions issue was addressed with improved validation

CVE-2022-22599 2.4 - Low - March 18, 2022

Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.

Incorrect Permission Assignment for Critical Resource

A cross-origin issue in the IndexDB API was addressed with improved input validation

CVE-2022-22594 6.5 - Medium - March 18, 2022

A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

Origin Validation Error

A validation issue was addressed with improved input sanitization

CVE-2022-22589 6.1 - Medium - March 18, 2022

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.

Improper Input Validation

An issue existed within the path validation logic for symlinks

CVE-2022-22585 7.5 - High - March 18, 2022

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access a user's files.

insecure temporary file

A memory corruption issue was addressed with improved validation

CVE-2022-22584 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.

Memory Corruption

A logic issue was addressed with improved validation

CVE-2022-22578 7.8 - High - March 18, 2022

A logic issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. A malicious application may be able to gain root privileges.

Improper Privilege Management

A memory corruption issue was addressed with improved validation

CVE-2022-22596 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

CVE-2022-23308 7.5 - High - February 26, 2022

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

Dangling pointer

A race condition was addressed with additional validation

CVE-2017-13905 8.1 - High - December 23, 2021

A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.

Race Condition

A memory corruption issue was addressed with improved memory handling

CVE-2017-13880 7.8 - High - December 23, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An application may be able to execute arbitrary code with kernel privilege.

A null pointer dereference was addressed with improved validation

CVE-2018-4302 7.8 - High - December 23, 2021

A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.

NULL Pointer Dereference

A logic issue was addressed with improved state management

CVE-2021-30767 5.5 - Medium - December 23, 2021

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A local user may be able to modify protected parts of the file system.

This issue was addressed with improved entitlements

CVE-2019-8703 9.8 - Critical - December 23, 2021

This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macOS Catalina 10.15, iOS 13. An application may be able to gain elevated privileges.

This issue was addressed with improved checks

CVE-2021-30840 7.8 - High - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

An out-of-bounds read was addressed with improved input validation

CVE-2021-30836 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30834 7.8 - High - October 28, 2021

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, Security Update 2021-007 Catalina. Processing a malicious audio file may result in unexpected application termination or arbitrary code execution.

An out-of-bounds read was addressed with improved input validation

CVE-2021-30831 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted font may result in the disclosure of process memory.

Out-of-bounds Read

A logic issue was addressed with improved restrictions

CVE-2021-30823 6.5 - Medium - October 28, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.

A type confusion issue was addressed with improved state handling

CVE-2021-30818 8.8 - High - October 28, 2021

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Object Type Confusion

A memory corruption issue was addressed with improved input validation

CVE-2021-30814 7.8 - High - October 28, 2021

A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2021-30809 8.8 - High - October 28, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

This issue was addressed with improved checks

CVE-2021-30808 5.5 - Medium - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A malicious application may be able to modify protected parts of the file system.

A logic issue was addressed with improved state management

CVE-2021-1821 6.5 - Medium - October 28, 2021

A logic issue was addressed with improved state management. This issue is fixed in watchOS 7.6, macOS Big Sur 11.5. Visiting a maliciously crafted webpage may lead to a system denial of service.

This issue was addressed with improved checks

CVE-2021-30847 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

Multiple memory corruption issues were addressed with improved memory handling

CVE-2021-30849 7.8 - High - October 19, 2021

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

This issue was addressed with improved checks

CVE-2021-30835 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30841 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30842 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30843 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30846 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

An authorization issue was addressed with improved state management

CVE-2021-30810 4.3 - Medium - October 19, 2021

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.

AuthZ

This issue was addressed with improved checks

CVE-2021-30811 5.5 - Medium - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker may be able to read sensitive information.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30807 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

This issue was addressed with improved environment sanitization

CVE-2021-30677 8.8 - High - September 08, 2021

This issue was addressed with improved environment sanitization. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to break out of its sandbox.

This issue was addressed with improved checks

CVE-2021-30707 8.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. Processing a maliciously crafted audio file may lead to arbitrary code execution.

Classic Buffer Overflow

A memory corruption issue was addressed with improved state management

CVE-2021-30710 7.1 - High - September 08, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may cause a denial of service or potentially disclose memory contents.

Memory Corruption

This issue was addressed with improved checks

CVE-2021-1814 7.8 - High - September 08, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple Watch OS or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple Watch OS
Apple Watch Operating System

subscribe