First published: Tue Jan 26 2021(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.
Credit: Peter Nguyen STAR LabsPeter Nguyen STAR LabsPeter Nguyen STAR LabsPeter Nguyen STAR Labs product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <14.4 | 14.4 |
Apple iPadOS | <14.4 | 14.4 |
Apple macOS Big Sur | <11.2 | 11.2 |
Apple Catalina | ||
Apple Mojave | ||
Apple watchOS | <7.3 | 7.3 |
Apple tvOS | <14.4 | 14.4 |
Apple iPadOS | <14.4 | |
Apple iPhone OS | <14.4 | |
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-security_update_2020-007 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.2 | |
Apple tvOS | <14.4 | |
Apple watchOS | <7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-1758 is a vulnerability in the FontParser component that allows for an out-of-bounds read.
The severity of CVE-2021-1758 is not specified in the provided information.
macOS Big Sur (up to version 11.2), Apple Catalina, Apple Mojave, Apple watchOS (up to version 7.3), Apple iOS (up to version 14.4), Apple iPadOS (up to version 14.4), and Apple tvOS (up to version 14.4) are affected by CVE-2021-1758.
To fix CVE-2021-1758, it is recommended to update your software to the latest version provided by Apple.
You can find more information about CVE-2021-1758 at the following references: [https://support.apple.com/en-us/HT212149](https://support.apple.com/en-us/HT212149), [https://support.apple.com/en-us/HT212147](https://support.apple.com/en-us/HT212147), [https://support.apple.com/en-us/HT212148](https://support.apple.com/en-us/HT212148).