First published: Tue Jan 26 2021(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate their privileges.
Credit: Proteas Pan ZhenPeng @Peterpan0927 Alibaba SecurityPan ZhenPeng @Peterpan0927 Alibaba SecurityProteas Proteas Pan ZhenPeng @Peterpan0927 Alibaba SecurityProteas Pan ZhenPeng @Peterpan0927 Alibaba Security product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <14.4 | |
Apple iPhone OS | <14.4 | |
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-004 | |
Apple Mac OS X | =10.14.6-security_update_2019-005 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-security_update_2020-007 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.2 | |
Apple tvOS | <14.4 | |
Apple watchOS | <7.3 | |
Apple tvOS | <14.4 | 14.4 |
Apple watchOS | <7.3 | 7.3 |
Apple iOS | <14.4 | 14.4 |
Apple iPadOS | <14.4 | 14.4 |
Apple macOS Big Sur | <11.2 | 11.2 |
Apple Catalina | ||
Apple Mojave |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-1757 is a vulnerability in IOSkywalkFamily that allows an out-of-bounds read.
The affected Apple products include macOS Big Sur 11.2, Catalina, Mojave, watchOS up to 7.3, iOS up to 14.4, iPadOS up to 14.4, and tvOS up to 14.4.
The severity of CVE-2021-1757 is dependent on the specific use case and attacker's capabilities.
To fix CVE-2021-1757, it is recommended to update your Apple devices to the latest available version, which includes the necessary patches.
You can find more information about CVE-2021-1757 on Apple's official security advisory pages: [link 1](https://support.apple.com/en-us/HT212147), [link 2](https://support.apple.com/en-us/HT212148), and [link 3](https://support.apple.com/en-us/HT212146).