First published: Tue Aug 24 2021(Updated: )
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.
Credit: Samuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project ZeroSamuel Groß Google Project Zero cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <15.0 | |
Apple iPadOS | <15.0 | |
Apple iPhone OS | <15.0 | |
Apple macOS | <12.0.1 | |
Apple macOS | =12.0.1 | |
Apple tvOS | <15.0 | |
Apple watchOS | <8.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.40.5-1~deb11u1 2.42.1-1~deb11u2 2.40.5-1~deb12u1 2.42.1-1~deb12u1 2.42.1-2 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.42.1-1 | |
Apple Safari | <15 | 15 |
Apple iOS | <15 | 15 |
Apple iPadOS | <15 | 15 |
Apple watchOS | <8 | 8 |
Apple tvOS | <15 | 15 |
Apple macOS Monterey | <12.0.1 | 12.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30851 is a memory corruption vulnerability in WebKit that has been addressed with improved locking.
CVE-2021-30851 affects watchOS up to version 8, iOS up to version 15, iPadOS up to version 15, tvOS up to version 15, Safari up to version 15, and macOS Monterey up to version 12.0.1.
To fix CVE-2021-30851, update your operating system and Safari to the latest available version.
You can find more information about CVE-2021-30851 on Apple's support website at the following links: [HT212814](https://support.apple.com/en-us/HT212814), [HT212819](https://support.apple.com/en-us/HT212819), and [HT212815](https://support.apple.com/en-us/HT212815).