Input validation error in macOS - CVE-2021-1843
Published: April 27, 2021
Vulnerability identifier: #VU52615
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1843
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the ImageIO component. A remote attacker can create a specially crafted image, trick the victim into opening it and execute arbitrary code on the system.
Affected software
macOS
watchOS
iPadOS
tvOS
Apple iOS
watchOS
iPadOS
tvOS
Apple iOS
How to mitigate CVE-2021-1843
Install updates from vendor's website.
macOS - addressed in versions 10.14.6 18G9028, 10.15.7 19H1030, 11.3 20E232
watchOS - update to 7.4 18T195
iPadOS - update to 14.5 18E199
tvOS - update to 14.5 18L204
Apple iOS - update to 14.5 18E199
watchOS - update to 7.4 18T195
iPadOS - update to 14.5 18E199
tvOS - update to 14.5 18L204
Apple iOS - update to 14.5 18E199