Garmin's vulnerability profile centers on a modestly represented but prominent portfolio of wearable devices, fitness trackers, and connected applications such as Connect IQ and Forerunner, where firmware and software updates often lag across installed bases. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety and authorization weakness classes including classic buffer overflows, integer overflows, improper array indexing, and incorrect authorization checks that are typical of embedded and mobile firmware. Defenders should prioritize inventory of Garmin wearables and connected devices, particularly those in extended service life, and monitor firmware release schedules closely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Garmin over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27851CRITICAL The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control | May 13, 2026 | 9.3 | 30 | NO | NO |
CVE-2023-23306CRITICAL The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operatio | May 23, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-27484CRITICAL Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a | Nov 16, 2020 | 9.9 | 30 | NO | NO |
CVE-2023-23305CRITICAL The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding special | May 23, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-23302CRITICAL The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying var | May 23, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-23300CRITICAL The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying da | May 23, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-23298CRITICAL The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when alloc | May 23, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-27485CRITICAL Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a | Nov 16, 2020 | 9.9 | 28 | NO | NO |
CVE-2020-27483CRITICAL Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a | Nov 16, 2020 | 9.9 | 28 | NO | NO |
CVE-2023-23303CRITICAL The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copyin | May 23, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Garmin.
Media articles that mention a CVE ID that affects a product developed by Garmin — matched by CVE ID, not by vendor name.