Improper Initialization in macOS - CVE-2021-1857
Published: April 27, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper initialization within the CFNetwork component when processing crafted web content. A remote attacker can trick the victim to open a specially crafted webpage, trigger memory corruption and gain access to sensitive information.
Affected software
watchOS
iPadOS
tvOS
Apple iOS
iCloud for Windows
iTunes
How to mitigate CVE-2021-1857
watchOS - update to 7.4 18T195
iPadOS - update to 14.5 18E199
tvOS - update to 14.5 18L204
Apple iOS - update to 14.5 18E199
iCloud for Windows - update to 12.3
iTunes - update to 12.11.3