First published: Tue Jan 26 2021(Updated: )
ImageIO. This issue was addressed with improved checks.
Credit: Mickey Jin & Qi Sun Trend Micro working with Trend MicroXingwei Lin Ant Security LightXingwei Lin Ant Security LightMickey Jin & Qi Sun Trend Micro working with Trend Micro Jeonghoon Shin @singi21a THEORIXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightJeonghoon Shin @singi21a THEORIMickey Jin & Qi Sun Trend Micro working with Trend MicroXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightJeonghoon Shin @singi21a THEORIMickey Jin & Qi Sun Trend Micro working with Trend MicroXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightJeonghoon Shin @singi21a THEORIMickey Jin & Qi Sun Trend Micro working with Trend MicroXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security Light product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <14.4 | |
Apple iPhone OS | <14.4 | |
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-004 | |
Apple Mac OS X | =10.14.6-security_update_2019-005 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-security_update_2020-007 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.2 | |
Apple tvOS | <14.4 | |
Apple watchOS | <7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-1754 is a vulnerability in ImageIO that allows for arbitrary code execution.
CVE-2021-1754 affects macOS Big Sur version 11.2 and below, allowing for arbitrary code execution.
CVE-2021-1754 affects watchOS version 7.3 and below, allowing for arbitrary code execution.
To fix CVE-2021-1754 on macOS Big Sur, update to version 11.3 or later.
To fix CVE-2021-1754 on watchOS, update to version 7.4 or later.