First published: Tue Aug 24 2021(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Playing a malicious audio file may lead to arbitrary code execution.
Credit: JunDong Xie Ant Security LightJunDong Xie Ant Security LightJunDong Xie Ant Security LightJunDong Xie Ant Security LightJunDong Xie Ant Security LightJunDong Xie Ant Security Light cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Monterey | <12.1 | 12.1 |
Apple Catalina | ||
Apple iOS | <15.2 | 15.2 |
Apple iPadOS | <15.2 | 15.2 |
Apple macOS | <11.6.2 | 11.6.2 |
watchOS | <8.3 | 8.3 |
Apple iPadOS | <15.2 | |
Apple iPhone OS | <15.2 | |
macOS Yosemite | >=10.15<10.15.7 | |
macOS Yosemite | =10.15.7 | |
macOS Yosemite | =10.15.7-security_update_2020-001 | |
macOS Yosemite | =10.15.7-security_update_2021-001 | |
macOS Yosemite | =10.15.7-security_update_2021-002 | |
macOS Yosemite | =10.15.7-security_update_2021-003 | |
macOS Yosemite | =10.15.7-security_update_2021-004 | |
macOS Yosemite | =10.15.7-security_update_2021-005 | |
macOS Yosemite | =10.15.7-security_update_2021-006 | |
macOS Yosemite | =10.15.7-security_update_2021-007 | |
Apple macOS | >=11.0<11.6.2 | |
Apple macOS | >=12.0<12.1 | |
tvOS | <15.2 | |
watchOS | <8.3 | |
tvOS | <15.2 | 15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30958 is a vulnerability in CoreAudio that allows for an out-of-bounds read due to improved input validation. It affects various Apple products including macOS, iOS, and watchOS.
The severity of CVE-2021-30958 is not specified, but it is classified under CWE-20, which is the Common Weakness Enumeration for Improper Input Validation.
CVE-2021-30958 affects Apple Catalina, macOS Monterey (up to version 12.1), macOS Big Sur (up to version 11.6.2), watchOS (up to version 8.3), iOS (up to version 15.2), iPadOS (up to version 15.2), and tvOS (up to version 15.2).
To fix CVE-2021-30958, it is recommended to update your affected Apple products to the latest available versions.
You can find more information about CVE-2021-30958 on the official Apple support page at https://support.apple.com/en-us/HT212980.