20210917 APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8mailing list
http://seclists.org/fulldisclosure/2021/Sep/25 CVE-2021-30860
HIGHCISA KEV
Apple Multiple Products Integer Overflow Vulnerability
Record summary
CVE-2021-30860 has a selected CVSS score of 7.8 (high); EIP currently links 3 repository PoCs. CISA lists CVE-2021-30860 in KEV.
Description
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Sep 7, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 3
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
| CVE List | Before 14.8 | affected | |
macOSBrowse Apple / macOS | CVE List | Before 11.6 | affected |
| Before 2021-005 | affected | ||
watchOSBrowse Apple / watchOS | CVE List | Before 7.6 | affected |
Proofs of concept
3Repository PoCs
GitHubLevilutz/CVE-2021-30860Repository PoCby LevilutzStars: 11Not analyzed7 files
GitHub30440r/gexRepository PoCby 30440rStars: 5Not analyzed12 files
GitHubjeffssh/CVE-2021-30860Repository PoCby jeffsshStars: 100Not analyzed32 files
References
Showing 12 of 1620210917 APPLE-SA-2021-09-13-2 watchOS 7.6.2mailing list
http://seclists.org/fulldisclosure/2021/Sep/26 20210917 APPLE-SA-2021-09-13-3 macOS Big Sur 11.6mailing list
http://seclists.org/fulldisclosure/2021/Sep/27 20210917 APPLE-SA-2021-09-13-4 Security Update 2021-005 Catalinamailing list
http://seclists.org/fulldisclosure/2021/Sep/28 20210921 APPLE-SA-2021-09-20-6 Additional information for APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8mailing list
http://seclists.org/fulldisclosure/2021/Sep/38 20210921 APPLE-SA-2021-09-20-7 Additional information for APPLE-SA-2021-09-13-3 macOS Big Sur 11.6mailing list
http://seclists.org/fulldisclosure/2021/Sep/39 20210921 APPLE-SA-2021-09-20-8 Additional information for APPLE-SA-2021-09-13-4 Security Update 2021-005 Catalinamailing list
http://seclists.org/fulldisclosure/2021/Sep/40 20210924 APPLE-SA-2021-09-23-1 iOS 12.5.5mailing list
http://seclists.org/fulldisclosure/2021/Sep/50 [oss-security] 20220902 JBIG2 integer overflow fixed in Xpdf 4.04, Poppler 22.09.0mailing list
http://www.openwall.com/lists/oss-security/2022/09/02/11 GLSA-202209-21Vendor advisory
https://security.gentoo.org/glsa/202209-21 support.apple.com
https://support.apple.com/en-us/HT212804 support.apple.com
https://support.apple.com/en-us/HT212805