Out-of-Bounds Read Vulnerability in Apple iOS, macOS, watchOS, and tvOS
CVE-2021-30789

7.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
8 September 2021

Summary

An out-of-bounds read vulnerability exists within Apple products due to improper input validation when processing specially crafted font files. This flaw could allow an attacker to execute arbitrary code on the device, posing a significant security risk. Updates provided in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, and in Security Update 2021-004 for Catalina address this critical issue, enhancing overall system security.

Affected Version(s)

iOS < 14.7

macOS < 11.5

macOS < 14.7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.