Accessibility. A logic issue was addressed with improved restrictions.
A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.
ImageIO. This issue was addressed with improved checks.
ImageIO. This issue was addressed with improved checks.
A flaw was found in WebKitGTK. Processing maliciously crafted web content may lead to arbitrary code execution.
References: https://webkitgtk.org/security/WSA-2021-0006.html https://www.openwall.com/lists/oss-security/2021/10/26/9
CoreGraphics. A memory corruption issue was addressed with improved input validation.
Foundation. A type confusion issue was addressed with improved memory handling.
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
ImageIO. An out-of-bounds read was addressed with improved input validation.
ImageIO. An out-of-bounds read was addressed with improved input validation.
ImageIO. An out-of-bounds read was addressed with improved input validation.
A flaw was found in WebKitGTK.
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A use after free issue was addressed with improved memory management.
Reference: https://webkitgtk.org/security/WSA-2021-0002.html
SQLite. This issue was addressed with improved checks.
A flaw was found in WebKitGTK. An input validation issue was addressed with improved input validation. Processing maliciously crafted web content may lead to a cross site scripting attack.
Reference: https://webkitgtk.org/security/WSA-2020-0008.html
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iTunes for Windows 12.10.9. Processing a maliciously crafted text file may lead to arbitrary code execution.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iCloud for Windows 11.4, iOS 14.0 and iPadOS 14.0, watchOS 7.0, tvOS 14.0, iCloud for Windows 7.21, iTunes for Windows 12.10.9. Processing a maliciously crafted tiff file may lead to a denial-of-service or potentially disclose memory contents.
A flaw was found in WebKitGTK.
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A use after free issue was addressed with improved memory management.
Reference: https://webkitgtk.org/security/WSA-2021-0002.html
A flaw was found in WebKitGTK. An use after free issue was addressed with improved memory management. Processing maliciously crafted web content may lead to arbitrary code execution.
Reference: https://webkitgtk.org/security/WSA-2020-0008.html
A flaw was found in WebKitGTK. Processing maliciously crafted web content may lead to a cross site scripting attack. Description: An input validation issue was addressed with improved input validation.
Reference: https://webkitgtk.org/security/WSA-2020-0008.html
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
CoreGraphics. A buffer overflow issue was addressed with improved memory handling.
ImageIO. A memory corruption issue was addressed with improved input validation.
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
ImageIO. An out-of-bounds write issue was addressed with improved bounds checking.
ImageIO. A buffer overflow issue was addressed with improved memory handling.