Buffer overflow in macOS - CVE-2021-1882
Published: April 27, 2021
Vulnerability identifier: #VU52614
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1882
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the Foundation component. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code on the system with root privileges.
Affected software
macOS
watchOS
iPadOS
tvOS
Apple iOS
watchOS
iPadOS
tvOS
Apple iOS
How to mitigate CVE-2021-1882
Install updates from vendor's website.
macOS - addressed in versions 10.15.7 19H1030, 11.3 20E232
watchOS - update to 7.4 18T195
iPadOS - update to 14.5 18E199
tvOS - update to 14.5 18L204
Apple iOS - update to 14.5 18E199
watchOS - update to 7.4 18T195
iPadOS - update to 14.5 18E199
tvOS - update to 14.5 18L204
Apple iOS - update to 14.5 18E199