PT-2021-4454 · Apple+1 · Ipados+5

Published

2021-08-24

·

Updated

2026-04-13

·

CVE-2021-30860

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions iOS versions prior to 14.8 iPadOS versions prior to 14.8 watchOS versions prior to 7.6.2 Mac OS versions prior to Security Update 2021-005 Catalina, macOS Big Sur 11.6
Description The issue is caused by an integer overflow that can be exploited by opening a maliciously crafted PDF file, potentially allowing a remote attacker to execute arbitrary code on the target system. Apple is aware of reports that this issue may have been actively exploited. The vulnerability can be triggered on devices running versions prior to the specified fixed versions.
Recommendations For iOS versions prior to 14.8, update to iOS 14.8 or later. For iPadOS versions prior to 14.8, update to iPadOS 14.8 or later. For watchOS versions prior to 7.6.2, update to watchOS 7.6.2 or later. For Mac OS versions prior to Security Update 2021-005 Catalina, apply Security Update 2021-005 Catalina or update to macOS Big Sur 11.6 or later. As a temporary workaround, consider avoiding the use of PDF files from untrusted sources until the issue is resolved.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2022_7594
ALSA-2022_8151
ALSA-2023_2259
ALSA-2023_2810
ALT-PU-2022-1867
ALT-PU-2022-2449
ALT-PU-2022-3233
ALT-PU-2023-1100
BDU:2021-05087
BDU:2022-05310
CVE-2021-30860
JLSEC-2025-195
JLSEC-2026-80
JLSEC-2026-81

Affected Products

Alt Linux
Apple Macos
Ios
Ipados
Macos Big Sur
Watchos