A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 06:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2021/Sep/25 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/27 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/29 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/38 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/39 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/50 - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2021/09/20/1 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/26/9 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/27/1 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/27/2 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/27/4 - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO6DMTHZR57JDBOXPSNR2MKDMCRWV265/ - Release Notes | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XYNV7ASK4LQVAUMJXNXBS3Z7RVDQ2N3W/ - Release Notes | |
References | () https://support.apple.com/en-us/HT212804 - Third Party Advisory | |
References | () https://support.apple.com/en-us/HT212807 - Third Party Advisory | |
References | () https://support.apple.com/kb/HT212824 - Third Party Advisory | |
References | () https://www.debian.org/security/2021/dsa-4975 - Mailing List, Third Party Advisory | |
References | () https://www.debian.org/security/2021/dsa-4976 - Mailing List, Third Party Advisory |
29 Jul 2024, 18:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2021/Sep/25 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/27 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/29 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/38 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/39 - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2021/Sep/50 - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2021/09/20/1 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/26/9 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/27/1 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/27/2 - Mailing List | |
References | () http://www.openwall.com/lists/oss-security/2021/10/27/4 - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO6DMTHZR57JDBOXPSNR2MKDMCRWV265/ - Release Notes | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XYNV7ASK4LQVAUMJXNXBS3Z7RVDQ2N3W/ - Release Notes | |
References | () https://support.apple.com/en-us/HT212804 - Third Party Advisory | |
References | () https://support.apple.com/en-us/HT212807 - Third Party Advisory | |
References | () https://support.apple.com/kb/HT212824 - Third Party Advisory | |
References | () https://www.debian.org/security/2021/dsa-4975 - Mailing List, Third Party Advisory | |
References | () https://www.debian.org/security/2021/dsa-4976 - Mailing List, Third Party Advisory |
03 Dec 2021, 02:27
Type | Values Removed | Values Added |
---|---|---|
References | (FULLDISC) http://seclists.org/fulldisclosure/2021/Sep/50 - Mailing List, Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2021/09/20/1 - Mailing List, Third Party Advisory | |
References | (FULLDISC) http://seclists.org/fulldisclosure/2021/Sep/25 - Mailing List, Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2021/10/26/9 - Mailing List, Third Party Advisory | |
References | (CONFIRM) https://support.apple.com/kb/HT212824 - Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BO6DMTHZR57JDBOXPSNR2MKDMCRWV265/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XYNV7ASK4LQVAUMJXNXBS3Z7RVDQ2N3W/ - Mailing List, Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2021/10/27/4 - Mailing List, Third Party Advisory | |
References | (FULLDISC) http://seclists.org/fulldisclosure/2021/Sep/38 - Mailing List, Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2021/10/27/1 - Mailing List, Third Party Advisory | |
References | (FULLDISC) http://seclists.org/fulldisclosure/2021/Sep/39 - Mailing List, Third Party Advisory | |
References | (FULLDISC) http://seclists.org/fulldisclosure/2021/Sep/27 - Mailing List, Third Party Advisory | |
References | (FULLDISC) http://seclists.org/fulldisclosure/2021/Sep/29 - Mailing List, Third Party Advisory | |
References | (DEBIAN) https://www.debian.org/security/2021/dsa-4975 - Third Party Advisory | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2021/10/27/2 - Mailing List, Third Party Advisory | |
References | (DEBIAN) https://www.debian.org/security/2021/dsa-4976 - Third Party Advisory | |
CPE | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
27 Oct 2021, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Oct 2021, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Oct 2021, 06:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Oct 2021, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Oct 2021, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Sep 2021, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Sep 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Sep 2021, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Sep 2021, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Sep 2021, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Sep 2021, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
17 Sep 2021, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 Sep 2021, 12:55
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://support.apple.com/en-us/HT212804 - Release Notes, Vendor Advisory | |
References | (MISC) https://support.apple.com/en-us/HT212807 - Release Notes, Vendor Advisory | |
CPE | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
|
CWE | CWE-416 | |
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.8 |
14 Sep 2021, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | |
References |
|
24 Aug 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-24 19:15
Updated : 2025-01-29 18:15
NVD link : CVE-2021-30858
Mitre link : CVE-2021-30858
CVE.ORG link : CVE-2021-30858
JSON object : View
Products Affected
fedoraproject
- fedora
apple
- iphone_os
- macos
- ipados
debian
- debian_linux
CWE
CWE-416
Use After Free