First published: Mon Sep 20 2021(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted font may result in the disclosure of process memory.
Credit: Xingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security LightXingwei Lin Ant Security Light product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <15 | 15 |
Apple iPadOS | <15 | 15 |
Apple tvOS | <15 | 15 |
Apple watchOS | <8 | 8 |
Apple macOS Monterey | <12.0.1 | 12.0.1 |
Apple iPadOS | <15.0 | |
Apple iPhone OS | <15.0 | |
Apple macOS | <12.0.1 | |
Apple tvOS | <15.0 | |
Apple watchOS | <8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30831 is a vulnerability in the FontParser component that allows for an out-of-bounds read due to improved input validation.
CVE-2021-30831 affects Apple watchOS up to version 8, Apple iOS up to version 15, Apple iPadOS up to version 15, Apple macOS Monterey up to version 12.0.1, and Apple tvOS up to version 15.
The severity of CVE-2021-30831 is not mentioned in the provided information.
To fix CVE-2021-30831, it is recommended to update your affected software to the latest version provided by Apple.
More information about CVE-2021-30831 can be found on the official Apple support page at the following links: [support.apple.com/en-us/HT212814](support.apple.com/en-us/HT212814), [support.apple.com/en-us/HT212819](support.apple.com/en-us/HT212819), [support.apple.com/en-us/HT212815](support.apple.com/en-us/HT212815).