First published: Mon Sep 13 2021(Updated: )
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
Credit: Sergei Glazunov Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.40.5-1~deb11u1 2.42.1-1~deb11u2 2.40.5-1~deb12u1 2.42.1-1~deb12u1 2.42.1-2 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.42.1-1 | |
Apple macOS Monterey | <12.0.1 | 12.0.1 |
tvOS | <15 | 15 |
Apple Mobile Safari | <15 | 15 |
Apple iOS, iPadOS, and watchOS | <14.8 | 14.8 |
Apple iOS, iPadOS, and watchOS | <14.8 | 14.8 |
Apple iOS, iPadOS, and watchOS | <15 | 15 |
Apple iOS, iPadOS, and watchOS | <15 | 15 |
Apple iOS, iPadOS, and watchOS | <8 | 8 |
Apple Mobile Safari | <15.0 | |
Apple iOS, iPadOS, and watchOS | <14.8 | |
iStyle @cosme iPhone OS | <14.8 | |
Apple iOS and macOS | <12.0.1 | |
tvOS | <15.0 | |
Apple iOS, iPadOS, and watchOS | <8.0 | |
Debian | =10.0 | |
Debian | =11.0 | |
Fedora | =33 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2021-30846.
The affected software versions include Apple watchOS up to version 8, Apple iOS up to version 15, Apple iPadOS up to version 15, Apple iOS up to version 14.8, Apple iPadOS up to version 14.8, Apple tvOS up to version 15, Apple Safari up to version 15, and Apple macOS Monterey up to version 12.0.1.
The severity of CVE-2021-30846 has not been disclosed.
To fix the vulnerability, it is recommended to update your software to the latest version provided by Apple. Please refer to the Apple support links provided for more information on the available updates.
You can find more information about CVE-2021-30846 on the Apple support pages. Please refer to the provided reference links.