First published: Tue Jan 26 2021(Updated: )
WebKit. A type confusion issue was addressed with improved state handling.
Credit: @S0rryMybad 360 Vulcan Team @S0rryMybad 360 Vulcan Team @S0rryMybad 360 Vulcan Team product-security@apple.com @S0rryMybad 360 Vulcan Team @S0rryMybad 360 Vulcan Team product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Multiple Products | ||
tvOS | <14.4 | 14.4 |
Apple macOS | <11.2 | 11.2 |
macOS Catalina | ||
macOS Mojave | ||
Apple Mobile Safari | <14.0.3 | 14.0.3 |
Apple iOS, iPadOS, and watchOS | <14.4 | 14.4 |
Apple iOS, iPadOS, and watchOS | <14.4 | 14.4 |
Apple iOS, iPadOS, and watchOS | <7.3 | 7.3 |
Apple iOS, iPadOS, and watchOS | <14.4 | |
iOS | <14.4 | |
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.7 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-004 | |
Apple iOS and macOS | =10.14.6-security_update_2019-005 | |
Apple iOS and macOS | =10.14.6-security_update_2019-006 | |
Apple iOS and macOS | =10.14.6-security_update_2019-007 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-003 | |
Apple iOS and macOS | =10.14.6-security_update_2020-004 | |
Apple iOS and macOS | =10.14.6-security_update_2020-005 | |
Apple iOS and macOS | =10.14.6-security_update_2020-006 | |
Apple iOS and macOS | =10.14.6-security_update_2020-007 | |
Apple iOS and macOS | =10.14.6-supplemental_update | |
Apple iOS and macOS | =10.14.6-supplemental_update_2 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-supplemental_update | |
Apple iOS and macOS | >=11.0<11.2 | |
tvOS | <14.4 | |
Apple iOS, iPadOS, and watchOS | <7.3 | |
Fedora | =32 | |
Fedora | =33 | |
WebKitGTK+ | <2.30.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2021-1789.
Multiple Apple products including Apple Multiple Products, Safari, macOS Big Sur, Catalina, Mojave, watchOS, iOS, iPadOS, and tvOS are affected.
The vulnerability allows processing of maliciously crafted web content, leading to arbitrary code execution.
Apply the available security updates or patches provided by Apple for the affected products.
You can find more information about this vulnerability on the following references: [Apple Support - HT212147](https://support.apple.com/en-us/HT212147), [Apple Support - HT212148](https://support.apple.com/en-us/HT212148), [Apple Support - HT212146](https://support.apple.com/en-us/HT212146).