First published: Mon Apr 26 2021(Updated: )
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Credit: yangkang &zerokeeper&bianliang @dnpushme 360 ATAyangkang @dnpushme 360 ATA product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 | |
Apple macOS | <11.3 | 11.3 |
tvOS | <14.5 | 14.5 |
Apple Mobile Safari | <14.1 | 14.1 |
Apple Mobile Safari | <14.1 | |
Apple iOS, iPadOS, and watchOS | <14.5 | |
iOS | <12.5.3 | |
iOS | >=14.0<14.5 | |
Apple iOS and macOS | >=11.0<11.3 | |
tvOS | <14.5 | |
Apple iOS, iPadOS, and watchOS | <7.4 | |
Apple iOS, iPadOS, and watchOS | <12.5.3 | 12.5.3 |
Apple iOS, iPadOS, and watchOS | <14.5 | 14.5 |
Apple iOS, iPadOS, and watchOS | <14.5 | 14.5 |
Apple Multiple Products | ||
Apple iOS, iPadOS, and watchOS | <7.4 | 7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30661 is a use-after-free vulnerability found in Apple iOS, iPadOS, macOS, watchOS, tvOS, and Safari WebKit Storage.
The severity of CVE-2021-30661 is not mentioned in the provided information.
CVE-2021-30661 allows for code execution when processing maliciously crafted web content.
Apple iOS, iPadOS, macOS, watchOS, tvOS, and Safari WebKit Storage are affected by CVE-2021-30661.
To fix CVE-2021-30661, update your Apple devices to the recommended versions provided by Apple.