First published: Mon Apr 26 2021(Updated: )
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Credit: yangkang @dnpushme 360 ATAyangkang &zerokeeper&bianliang @dnpushme 360 ATAyangkang @dnpushme 360 ATAyangkang @dnpushme 360 ATAyangkang @dnpushme 360 ATAyangkang &zerokeeper&bianliang @dnpushme 360 ATA product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <14.5 | 14.5 |
Apple iPadOS | <14.5 | 14.5 |
Apple Safari | <14.1 | 14.1 |
Apple tvOS | <14.5 | 14.5 |
<7.4 | 7.4 | |
Apple macOS Big Sur | <11.3 | 11.3 |
Apple iOS | <12.5.3 | 12.5.3 |
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 | |
Apple Safari | <14.1 | |
Apple iPadOS | <14.5 | |
Apple iPhone OS | <12.5.3 | |
Apple iPhone OS | >=14.0<14.5 | |
Apple macOS | >=11.0<11.3 | |
Apple tvOS | <14.5 | |
Apple watchOS | <7.4 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30661 is a use-after-free vulnerability found in Apple iOS, iPadOS, macOS, watchOS, tvOS, and Safari WebKit Storage.
The severity of CVE-2021-30661 is not mentioned in the provided information.
CVE-2021-30661 allows for code execution when processing maliciously crafted web content.
Apple iOS, iPadOS, macOS, watchOS, tvOS, and Safari WebKit Storage are affected by CVE-2021-30661.
To fix CVE-2021-30661, update your Apple devices to the recommended versions provided by Apple.