First published: Tue Aug 24 2021(Updated: )
ColorSync. A memory corruption issue in the processing of ICC profiles was addressed with improved input validation.
Credit: Jeremy Brown Jeremy Brown Jeremy Brown Jeremy Brown Mateusz Jurczyk Google Project ZeroJeremy Brown Mateusz Jurczyk Google Project ZeroJeremy Brown Mateusz Jurczyk Google Project ZeroJeremy Brown Mateusz Jurczyk Google Project Zero cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <14.8.1 | |
Apple iPhone OS | <14.8.1 | |
Apple Mac OS X | >=10.15<10.15.17 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2020-005 | |
Apple Mac OS X | =10.15.7-security_update_2020-007 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | <12.1 | |
Apple macOS | >=11.0<11.6.1 | |
Apple tvOS | <15.2 | |
Apple watchOS | <8.3 | |
Apple Catalina | ||
Apple macOS Big Sur | <11.6.1 | 11.6.1 |
Apple iOS | <14.8.1 | 14.8.1 |
Apple iPadOS | <14.8.1 | 14.8.1 |
Apple macOS Monterey | <12.1 | 12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30926 is a memory corruption issue in the processing of ICC profiles in ColorSync.
CVE-2021-30926 affects Apple Catalina, Apple macOS Big Sur (up to version 11.6.1), Apple macOS Monterey (up to version 12.1), Apple iOS (up to version 14.8.1), Apple iPadOS (up to version 14.8.1), Apple iOS (up to version 15.2), Apple iPadOS (up to version 15.2), Apple watchOS (up to version 8.3), and Apple tvOS (up to version 15.2).
To fix CVE-2021-30926, update your software to the versions specified by Apple.
You can find more information about CVE-2021-30926 on the following Apple support pages: [Link 1](https://support.apple.com/en-us/HT212978), [Link 2](https://support.apple.com/en-us/HT212980), [Link 3](https://support.apple.com/en-us/HT212871).
CVE-2021-30926 is classified under CWE-20 (Improper Input Validation).