Buffer overflow in macOS - CVE-2021-30737
Published: May 24, 2021 / Updated: June 14, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the ASN.1 decoder when processing TLS certificates. A remote attacker can trick the victim to visit a specially crafted website, trigger memory corruption with a specially crafted TLS certificate and execute arbitrary code on the system.
Affected software
watchOS
Apple iOS
iPadOS
tvOS
How to mitigate CVE-2021-30737
watchOS - update to 7.5 18T567
Apple iOS - addressed in versions 12.5.4 16H50, 14.6 18F72
iPadOS - update to 14.6 18F72
tvOS - update to 14.6 18L569
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple iOS and iPadOS
- Multiple vulnerabilities in Apple iOS 12
- Multiple vulnerabilities in Apple macOS Mojave
- Multiple vulnerabilities in Apple macOS Catalina