CVE-2023-32417: Apple watchOS

Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.

This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 9.5. An attacker with physical access to a locked Apple Watch may be able to view user photos or contacts via accessibility features.

Affected products

  • Apple watchOS: before 9.5 (fixed in 9.5)

Published 2023-06-23. Last modified 2026-06-17.