First published: Mon May 03 2021(Updated: )
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Credit: an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher product-security@apple.com an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <14.1 | 14.1 |
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.40.5-1~deb11u1 2.42.1-1~deb11u2 2.40.5-1~deb12u1 2.42.1-1~deb12u1 2.42.1-2 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.42.1-1 | |
Apple Safari | <14.1.1 | 14.1.1 |
Apple macOS Big Sur | <11.3.1 | 11.3.1 |
Apple tvOS | <14.6 | 14.6 |
Apple macOS | >=11.0<11.3.1 | |
Apple Safari | <14.1.1 | |
Apple iPadOS | >=14.0<14.5.1 | |
Apple iPhone OS | <12.5.3 | |
Apple iPhone OS | >=14.0<14.5.1 | |
Apple tvOS | <14.6 | |
Apple iOS | <12.5.3 | 12.5.3 |
Apple iOS | <14.5.1 | 14.5.1 |
Apple iPadOS | <14.5.1 | 14.5.1 |
Apple Multiple Products | ||
>=11.0<11.3.1 | ||
<14.1.1 | ||
>=14.0<14.5.1 | ||
<12.5.3 | ||
>=14.0<14.5.1 | ||
<14.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this Apple product vulnerability is CVE-2021-30663.
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit are affected by this vulnerability.
The severity of CVE-2021-30663 is not specified in the provided information.
The CVE-2021-30663 vulnerability can be exploited by processing maliciously crafted web content.
To fix the CVE-2021-30663 vulnerability, update to the recommended version provided by Apple.