First published: Mon Apr 26 2021(Updated: )
CoreAudio. An out-of-bounds read was addressed with improved input validation.
Credit: JunDong Xie Ant Security LightJunDong Xie Ant Security LightJunDong Xie Ant Security LightJunDong Xie Ant Security LightJunDong Xie Ant Security Light product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.3 | 11.3 |
tvOS | <14.5 | 14.5 |
macOS Catalina | ||
Apple iOS, iPadOS, and watchOS | <14.5 | 14.5 |
Apple iOS, iPadOS, and watchOS | <14.5 | 14.5 |
Apple iOS, iPadOS, and watchOS | <7.4 | 7.4 |
Apple iOS, iPadOS, and watchOS | <14.5 | |
iOS | <14.5 | |
Apple iOS and macOS | =10.15 | |
Apple iOS and macOS | =10.15.1 | |
Apple iOS and macOS | =10.15.2 | |
Apple iOS and macOS | =10.15.3 | |
Apple iOS and macOS | =10.15.4 | |
Apple iOS and macOS | =10.15.5 | |
Apple iOS and macOS | =10.15.6 | |
Apple iOS and macOS | =10.15.6 | |
Apple iOS and macOS | =10.15.6-supplemental_update | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-security_update_2020 | |
Apple iOS and macOS | =10.15.7-security_update_2020-001 | |
Apple iOS and macOS | =10.15.7-security_update_2020-005 | |
Apple iOS and macOS | =10.15.7-security_update_2020-007 | |
Apple iOS and macOS | =10.15.7-security_update_2021-001 | |
Apple iOS and macOS | >=11.0<11.3 | |
tvOS | <14.5 | |
Apple iOS, iPadOS, and watchOS | <7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-1846 is a vulnerability in CoreAudio that allows for an out-of-bounds read, which can result in disclosure of restricted memory.
CVE-2021-1846 affects Apple iOS (up to version 14.5), Apple iPadOS (up to version 14.5), Apple watchOS (up to version 7.4), Apple macOS Big Sur (up to version 11.3), Apple Catalina, and Apple tvOS (up to version 14.5).
CVE-2021-1846 can be exploited by processing a maliciously crafted audio file.
The severity of CVE-2021-1846 is currently not specified.
To fix CVE-2021-1846, update your software to the latest version provided by Apple.