PT-2021-7972 · Apple · Macos Big Sur+2

R3Df09

+3

·

Published

2021-08-24

·

Updated

2022-01-03

·

CVE-2021-30969

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions macOS Big Sur versions prior to 11.6.2 macOS Catalina versions prior to Security Update 2021-008
Description A path handling issue was addressed with improved validation. This issue may cause unexpected JavaScript execution from a file on disk when processing a maliciously crafted URL. The vulnerability is related to insufficient input validation in the Help Viewer component of macOS Big Sur, which may allow an attacker to execute arbitrary JavaScript code.
Recommendations For macOS Big Sur versions prior to 11.6.2, update to macOS Big Sur 11.6.2 or later to resolve the issue. For macOS Catalina versions prior to Security Update 2021-008, apply Security Update 2021-008 to resolve the issue. As a temporary workaround, consider restricting access to maliciously crafted URLs to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08037
CVE-2021-30969

Affected Products

Apple Macos
Macos Big Sur
Macos Catalina