First published: Mon Apr 26 2021(Updated: )
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.
Credit: Zhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Tencent Security Xuanwu LabYuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Tencent Security Xuanwu LabYuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Tencent Security Xuanwu LabYuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu LabZhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu Lab product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <14.5 | 14.5 |
Apple iPadOS | <14.5 | 14.5 |
<7.4 | 7.4 | |
Apple Catalina | ||
Apple Mojave | ||
Apple iPadOS | <14.5 | |
Apple iPhone OS | <14.5 | |
Apple Mac OS X | >=10.14<=10.14.5 | |
Apple Mac OS X | >=10.15<=10.15.5 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2019-004 | |
Apple Mac OS X | =10.14.6-security_update_2019-005 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-security_update_2020-007 | |
Apple Mac OS X | =10.14.6-security_update_2021-001 | |
Apple Mac OS X | =10.14.6-security_update_2021-002 | |
Apple Mac OS X | =10.15 | |
Apple Mac OS X | =10.15.6 | |
Apple Mac OS X | =10.15.6-supplemental_update | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2020-005 | |
Apple Mac OS X | =10.15.7-security_update_2020-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.3 | |
Apple tvOS | <14.5 | |
Apple watchOS | <7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-1739 is a vulnerability in Apple iOS, iPadOS, watchOS, macOS, tvOS, and Mojave that allows for a parsing issue in the handling of directory paths, which has been addressed with improved path validation.
The severity of CVE-2021-1739 is not specified.
Apple iOS up to and excluding version 14.5, Apple iPadOS up to and excluding version 14.5, Apple watchOS up to and excluding version 7.4, Apple macOS Big Sur up to and excluding version 11.3, Apple tvOS up to and excluding version 14.5, Apple Catalina, and Apple Mojave are affected by CVE-2021-1739.
To fix CVE-2021-1739, update your affected software versions to the specified remedies: iOS version 14.5, iPadOS version 14.5, watchOS version 7.4, macOS Big Sur version 11.3, and tvOS version 14.5.
You can find more information about CVE-2021-1739 on Apple's support page: [https://support.apple.com/en-us/HT212326](https://support.apple.com/en-us/HT212326).