CVE-2019-8764: Apple watchOS

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.

Affected products

  • Apple watchOS: before 6.1 (fixed in 6.1)
  • WebKitGTK Webkitgtk+: before 2.26.4 (fixed in 2.26.4)

Published 2019-12-18. Last modified 2026-06-17.