PT-2021-6009 · Apple · Watchos+5
Hjy79425575
·
Published
2021-10-25
·
Updated
2021-11-23
·
CVE-2021-30814
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 15
iPadOS versions prior to 15
watchOS versions prior to 8
tvOS versions prior to 15
Mac OS (affected versions not specified)
Description
The issue is related to a memory corruption problem due to a buffer overflow in the ImageIO component. This can be exploited by processing a maliciously crafted image, potentially leading to arbitrary code execution in the target system. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For iOS versions prior to 15, update to iOS 15 or later.
For iPadOS versions prior to 15, update to iPadOS 15 or later.
For watchOS versions prior to 8, update to watchOS 8 or later.
For tvOS versions prior to 15, update to tvOS 15 or later.
For Mac OS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imageio
Apple Macos
Ios
Ipados
Tvos
Watchos