Technology · Apple
Apple watchOS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 288 vulnerabilities in Apple watchOS: 0 in the last 7 days and 158 in the last 90 days, 68 of them critical and 62 exploited in the wild. The most recent, CVE-2026-86904, was published on 14 September 2026.
- Last 7 days
- 0
- Last 90 days
- 158
- Critical, all time
- 68
- Exploited in the wild
- 62
About Apple watchOS
An operating system developed by Apple for the Apple Watch.
Latest Apple watchOS vulnerabilities
- CVE-2026-86904: Apple iOS iPadOS watchOS cross-app tracking privacy issuehighCVSS 7.5EPSS 0.4%
- CVE-2026-86903: Apple iOS out-of-bounds read in kernel memorymediumCVSS 5.5EPSS 0.2%
- CVE-2026-86895: Apple CloudKit information disclosure in persistent account identifiershighCVSS 7.5EPSS 0.5%
- CVE-2026-86893: Apple iOS/iPadOS/tvOS/visionOS/watchOS permissions issue in CloudKitlowCVSS 3.3EPSS 0.1%
- CVE-2026-86891: Apple macOS Core Bluetooth authorization bypass allowing Bluetooth device information accesslowCVSS 3.5EPSS 0.2%
- CVE-2026-86888: Apple App Store permissions issue allowing persistent account identifier exposurelowCVSS 3.3EPSS 0.1%
- CVE-2026-86886: Apple iOS path traversal in system file accessmediumCVSS 5.5EPSS 0.2%
- CVE-2026-86884: Apple iOS and iPadOS App Store permissions issuemediumCVSS 5.5EPSS 0.1%
- CVE-2026-86882: Apple Accelerate Framework out-of-bounds write in image processingmediumCVSS 6.5EPSS 0.5%
- CVE-2026-86881: Apple iOS, iPadOS, and macOS certificate validation bypasscriticalCVSS 9.1EPSS 0.4%
- CVE-2026-86876: Apple Accelerate Framework out-of-bounds write in image processingmediumCVSS 5.2EPSS 0.1%
- CVE-2026-86870: Apple iOS, iPadOS, macOS, visionOS, watchOS heap buffer overflow in Accelerate FrameworkmediumCVSS 6.5EPSS 0.4%
- CVE-2026-84636: Apple iOS authorization bypass in state managementmediumCVSS 5.5EPSS 0.1%
- CVE-2026-84635: Apple Safari logic issue in state managementmediumCVSS 6.5EPSS 0.4%
- CVE-2026-84632: Apple iOS and macOS 3D model memory corruptionhighCVSS 7.3EPSS 0.2%
- CVE-2026-84630: Apple iOS, iPadOS, and macOS race condition in state handlingmediumCVSS 4.7EPSS 0.1%
- CVE-2026-84629: Apple iOS and iPadOS user fingerprinting vulnerabilityhighCVSS 7.5EPSS 0.4%
- CVE-2026-84628: Apple iOS Keychain access bypass in AccountsmediumCVSS 5.5EPSS 0.2%
- CVE-2026-84626: Apple iOS and iPadOS information disclosure via app enumerationlowCVSS 3.3EPSS 0.1%
- CVE-2026-84625: Apple iOS permissions issue allowing user fingerprintingcriticalCVSS 9.1EPSS 0.5%
- CVE-2026-84622: Apple iOS and iPadOS kernel memory disclosure via uninitialized memorymediumCVSS 6.2EPSS 0.2%
- CVE-2026-84620: Apple iOS and macOS integer overflow in 3D model processinghighCVSS 7.3EPSS 0.2%
- CVE-2026-84616: Apple iOS type confusion in memory handlingmediumCVSS 5.5EPSS 0.1%
- CVE-2026-84612: Apple iOS and iPadOS authorization bypass in device identifier accessmediumCVSS 5.5EPSS 0.2%
- CVE-2026-84611: Apple Accelerate Framework out-of-bounds write in 3D model processinghighCVSS 7.3EPSS 0.2%
Most severe Apple watchOS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-43300: Apple iOS, iPadOS, and macOS out-of-bounds write in Image I/Ocriticalexploited in the wildCVSS 10EPSS 4.5%
- CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-31277: Apple Multiple Products memory corruption in web content processingcriticalexploited in the wildCVSS 8.8EPSS 1.5%
- CVE-2021-30952: Apple Multiple Products integer overflow in WebKit content processingcriticalexploited in the wildCVSS 8.8EPSS 0.9%
- CVE-2025-43529: Apple WebKit use-after-free in multiple productscriticalexploited in the wildCVSS 8.8EPSS 0.2%
- CVE-2022-48503: Apple Multiple Products code execution in JavaScriptCorecriticalexploited in the wildCVSS 8.8EPSS 0.2%
- CVE-2023-37450: Apple Multiple Products WebKit Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2023-32373: Apple Multiple Products WebKit Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 62 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 14 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 82 | 5 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/watchos.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apple watchOS vulnerabilities", https://junglewise.ai/threats/technologies/watchos, 26 September 2026.