First published: Tue Aug 24 2021(Updated: )
A path handling issue was addressed with improved validation. This issue is fixed in Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. Processing a maliciously crafted URL may cause unexpected JavaScript execution from a file on disk.
Credit: Zhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu Lab cve@mitre.org Zhipeng Huo @R3dF09 Yuebin Sun @yuebinsun2020 Tencent Security Xuanwu Lab
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Big Sur | <11.6.2 | 11.6.2 |
Apple Catalina | ||
Apple Mac OS X | >=10.15<=10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-004 | |
Apple Mac OS X | =10.15.7-security_update_2021-005 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple macOS | >=11.0<11.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30969 is a path handling issue in Help Viewer that has been addressed with improved validation.
The affected software includes macOS Big Sur versions up to and exclusive of 11.6.2, and Apple Catalina.
To fix the path handling issue, you should update your macOS Big Sur to version 11.6.2 or later, and apply any relevant security patches provided by Apple.
You can find more information about CVE-2021-30969 on Apple's official support page at the following link: https://support.apple.com/en-us/HT212979