First published: Tue Jan 26 2021(Updated: )
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.
Credit: Xingwei Lin Ant Security LightLei Sun product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <14.4 | 14.4 |
Apple macOS | <11.2 | 11.2 |
macOS Catalina | ||
macOS Mojave | ||
Apple iOS, iPadOS, and watchOS | <14.4 | |
iOS | <14.4 | |
Apple iOS and macOS | >=10.15<10.15.7 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-security_update_2020-001 | |
Apple iOS and macOS | =10.15.7-supplemental_update | |
Apple iOS and macOS | >=11.0.1<11.2 | |
tvOS | <14.4 | |
Apple iOS, iPadOS, and watchOS | <7.3 | |
Apple iOS, iPadOS, and watchOS | <14.4 | 14.4 |
Apple iOS, iPadOS, and watchOS | <14.4 | 14.4 |
Apple iOS, iPadOS, and watchOS | <7.3 | 7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-1744 is a vulnerability in ImageIO that allows for an out-of-bounds write due to improved input validation.
CVE-2021-1744 affects Apple macOS Big Sur 11.2 and can result in an out-of-bounds write vulnerability.
CVE-2021-1744 impacts Apple watchOS versions up to exclusive 7.3.
The remedy for CVE-2021-1744 on Apple iOS is to update to version 14.4 or higher.
You can find more information about CVE-2021-1744 in Apple's security advisories: [link 1](https://support.apple.com/en-us/HT212149), [link 2](https://support.apple.com/en-us/HT212147), [link 3](https://support.apple.com/en-us/HT212148).