← Vulnerability feed

Vulnerability record · CVE-2019-8624 · published 18 December 2019

CVE-2019-8624: Apple watchos out-of-bounds read vulnerability

Apple · Watchos

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory.

7.5 CVSS 3.1 High EPSS 6.9% · top 6.1% CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score, v2 5.0
6.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacker may be able to leak memory.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-8624 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2025-24085Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS Use-After-Free Privilege EscalationA use-after-free flaw in Apple's operating systems was fixed through improved memory management in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15…KEVEPSS 18%analysed9.8CVE-2025-31200Apple OS media parsing memory corruption allows code executionA memory corruption flaw in Apple's audio stream processing was fixed with improved bounds checking across iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 19%analysed8.8CVE-2025-43529Apple WebKit use-after-free allows code execution via crafted web contentA use-after-free flaw in Apple's WebKit engine was fixed through improved memory management across Safari, iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 8.8%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2025-6558Chrome ANGLE and GPU input validation flaw enables sandbox escapeGoogle Chrome before 138.0.7204.157 fails to properly validate untrusted input in ANGLE and the GPU component, allowing a crafted HTML page to trigge…KEVEPSS 9.6%analysed8.8CVE-2022-48503Apple WebKit bounds check flaw allows code execution via web contentApple fixed an insufficient bounds-checking issue in WebKit across Safari, iOS, iPadOS, macOS, tvOS and watchOS. Processing malicious web content can…KEVEPSS 3.2%analysed

Source: NIST National Vulnerability Database (record CVE-2019-8624), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.