VulnerabilityModified
CVE-2021-1844
A memory corruption issue was addressed with improved validation.
HIGH 8.8EPSS 2.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.39% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/watchos · debian/debian linux · fedoraproject/fedora
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2021/Apr/55Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3L6ZZOU5JS7E3RFYGLP7UFLXCG7TNLU/
- https://support.apple.com/en-us/HT212220Vendor Advisory
- https://support.apple.com/en-us/HT212221Vendor Advisory
- https://support.apple.com/en-us/HT212222Vendor Advisory
- https://support.apple.com/en-us/HT212223Vendor Advisory
- https://support.apple.com/kb/HT212323Vendor Advisory
- https://www.debian.org/security/2021/dsa-4923Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Apr/55Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3L6ZZOU5JS7E3RFYGLP7UFLXCG7TNLU/
- https://support.apple.com/en-us/HT212220Vendor Advisory
- https://support.apple.com/en-us/HT212221Vendor Advisory
- https://support.apple.com/en-us/HT212222Vendor Advisory
- https://support.apple.com/en-us/HT212223Vendor Advisory
- https://support.apple.com/kb/HT212323Vendor Advisory
- https://www.debian.org/security/2021/dsa-4923Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.