<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apple Watch (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/apple-watch.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apple-watch-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apple Watch (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-10327 – A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (includ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10327</guid>
    <pubDate>Thu, 24 Oct 2024 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10327</strong></p>
  <p>A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the notification banner and selects an option, both options allow the authentication to succeed.  The ContextExtension feature is one…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-13903 – An issue was discovered in certain Apple products. iOS before 11.2.1 is affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-13903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-13903</guid>
    <pubDate>Mon, 25 Dec 2017 21:29:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-13903</strong></p>
  <p>An issue was discovered in certain Apple products. iOS before 11.2.1 is affected. tvOS before 11.2.1 is affected. The issue involves the "HomeKit" component. It allows remote attackers to modify the application state by leveraging incorrect message handling, as demonstrated by use of an Apple Watch to obtain an encryption key and unlock a door.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-13903">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
