First published: Tue Aug 24 2021(Updated: )
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.
Credit: Samuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project Zero cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.40.5-1~deb11u1 2.42.1-1~deb11u2 2.40.5-1~deb12u1 2.42.1-1~deb12u1 2.42.1-2 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.42.1-1 | |
tvOS | <15 | 15 |
Apple iOS, iPadOS, and watchOS | <8 | 8 |
macOS | <12.0.1 | 12.0.1 |
Safari | <15 | 15 |
Apple iOS and iPadOS | <15 | 15 |
Apple iOS, iPadOS, and macOS | <15 | 15 |
Safari | <15.0 | |
Apple iOS, iPadOS, and macOS | <15.0 | |
iPhone OS | <15.0 | |
macOS | <12.0.1 | |
macOS | =12.0.1 | |
tvOS | <15.0 | |
Apple iOS, iPadOS, and watchOS | <8.0 | |
Debian Linux | =10.0 | |
Debian Linux | =11.0 | |
Red Hat Fedora | =33 | |
Red Hat Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30851 is a memory corruption vulnerability in WebKit that has been addressed with improved locking.
CVE-2021-30851 affects watchOS up to version 8, iOS up to version 15, iPadOS up to version 15, tvOS up to version 15, Safari up to version 15, and macOS Monterey up to version 12.0.1.
To fix CVE-2021-30851, update your operating system and Safari to the latest available version.
You can find more information about CVE-2021-30851 on Apple's support website at the following links: [HT212814](https://support.apple.com/en-us/HT212814), [HT212819](https://support.apple.com/en-us/HT212819), and [HT212815](https://support.apple.com/en-us/HT212815).