First published: Mon May 24 2021(Updated: )
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6, watchOS 7.5, tvOS 14.6. Processing a maliciously crafted font file may lead to arbitrary code execution.
Credit: Mickey Jin @patch1t Trend MicroCFF Topsec Alpha TeamMickey Jin @patch1t Trend MicroCFF Topsec Alpha TeamMickey Jin @patch1t Trend MicroCFF Topsec Alpha TeamMickey Jin @patch1t Trend MicroCFF Topsec Alpha Team product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <7.5 | 7.5 |
Apple macOS Big Sur | <11.4 | 11.4 |
Apple iOS | <14.6 | 14.6 |
Apple iPadOS | <14.6 | 14.6 |
Apple tvOS | <14.6 | 14.6 |
Apple iPadOS | <14.6 | |
Apple iPhone OS | <14.6 | |
Apple macOS | >=11.0<11.4 | |
Apple tvOS | <14.6 | |
Apple watchOS | <7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30771 is a vulnerability in FontParser that allows an attacker to perform an out-of-bounds write.
Apple tvOS up to version 14.6 is affected by CVE-2021-30771.
Apple watchOS up to version 7.5 is affected by CVE-2021-30771.
Apple macOS Big Sur up to version 11.4 is affected by CVE-2021-30771.
Apple iOS up to version 14.6 is affected by CVE-2021-30771.
Apple iPadOS up to version 14.6 is affected by CVE-2021-30771.
The severity of CVE-2021-30771 is not specified.
To fix CVE-2021-30771 on Apple tvOS, update to version 14.6 or later.
To fix CVE-2021-30771 on Apple watchOS, update to version 7.5 or later.
To fix CVE-2021-30771 on Apple macOS Big Sur, update to version 11.4 or later.
To fix CVE-2021-30771 on Apple iOS, update to version 14.6 or later.
To fix CVE-2021-30771 on Apple iPadOS, update to version 14.6 or later.