First published: Mon Sep 13 2021(Updated: )
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
Credit: Amar Menezes @amarekano Zon8ResearchAmar Menezes @amarekano Zon8ResearchAmar Menezes @amarekano Zon8ResearchAmar Menezes @amarekano Zon8ResearchAmar Menezes @amarekano Zon8ResearchAmar Menezes @amarekano Zon8Research product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
<15.0 | ||
<14.8 | ||
<14.8 | ||
<12.0.1 | ||
<15.0 | ||
<8.0 | ||
Apple Safari | <15 | 15 |
Apple iOS | <15 | 15 |
Apple iPadOS | <15 | 15 |
Apple watchOS | <8 | 8 |
Apple tvOS | <15 | 15 |
Apple iOS | <14.8 | 14.8 |
Apple iPadOS | <14.8 | 14.8 |
Apple macOS Monterey | <12.0.1 | 12.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30818 is a type confusion issue in WebKit that has been addressed with improved state handling.
CVE-2021-30818 affects watchOS up to version 8, iOS up to version 15, iPadOS up to version 15, iOS up to version 14.8, iPadOS up to version 14.8, tvOS up to version 15, Safari up to version 15, and macOS Monterey up to version 12.0.1.
To fix the vulnerability, update your software to the latest version provided by Apple.
You can find more information about CVE-2021-30818 on the Apple support website.