First published: Mon May 24 2021(Updated: )
FontParser. Processing a maliciously crafted font may result in the disclosure of process memory
Credit: Xingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security Light product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | >=11.0<11.4 | |
Apple tvOS | <14.6 | |
Apple watchOS | <7.5 | |
Apple macOS Big Sur | <11.4 | 11.4 |
Apple watchOS | <7.5 | 7.5 |
Apple tvOS | <14.6 | 14.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30755 is a vulnerability in FontParser that allows for the disclosure of process memory when processing a maliciously crafted font.
Apple tvOS up to version 14.6, Apple watchOS up to version 7.5, and Apple macOS Big Sur up to version 11.4 are affected by CVE-2021-30755.
CVE-2021-30755 can be exploited by processing a specially crafted font, resulting in the disclosure of process memory.
The severity of CVE-2021-30755 is currently unknown.
Yes, Apple has released updates to address CVE-2021-30755. It is recommended to update to the latest version of the affected software.