Vulnerability Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Ipados | >= 13.1, < 14.8 |
| Apple | Iphone Os | < 12.5.5 |
| Apple | Macos | < 11.6 |
| Fedoraproject | Fedora | 33 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2021/Sep/25Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/27Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/29Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/38Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/39Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Sep/50Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/20/1Mailing List
- http://www.openwall.com/lists/oss-security/2021/10/26/9Mailing List
- http://www.openwall.com/lists/oss-security/2021/10/27/1Mailing List
- http://www.openwall.com/lists/oss-security/2021/10/27/2Mailing List
- http://www.openwall.com/lists/oss-security/2021/10/27/4Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproRelease Notes
- https://support.apple.com/en-us/HT212804Third Party Advisory
- https://support.apple.com/en-us/HT212807Third Party Advisory
FAQ
What is CVE-2021-30858?
CVE-2021-30858 is a vulnerability with a CVSS score of 8.8 (HIGH). A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitr...
How severe is CVE-2021-30858?
CVE-2021-30858 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-30858?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Ipados, Apple Iphone Os, Apple Macos, Fedoraproject Fedora, Debian Debian Linux.