Apple Security Advisories · February 2021 — Apple Security Advisories
63 advisories 63 CVEs 5 EXPLOITED

Apple-vendor CVEs for 2021-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 5 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-1789

iPadOSExploitedCISA KEV listedCRITICAL2021-02-02

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processin...

CVEs:CVE-2021-1789

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1870

iPadOSExploitedCISA KEV listedCRITICAL2021-02-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execu...

CVEs:CVE-2021-1870

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1871

iPadOSExploitedCISA KEV listedCRITICAL2021-02-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execu...

CVEs:CVE-2021-1871

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1801

iPadOSExploitedVulnCheck KEV listedCRITICAL2021-02-02

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Maliciously crafted web ...

CVEs:CVE-2021-1801

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1765

macOSExploitedVulnCheck KEV listedCRITICAL2021-02-02

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Maliciously crafted web content may violate iframe sandboxing policy.

CVEs:CVE-2021-1765

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1778

watchOSActive exploitation (sightings)HIGH2021-02-02

An out-of-bounds read issue existed in the curl. This issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and...

CVEs:CVE-2021-1778

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-23841

OtherPoC exploitCRITICAL2021-02-16

The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while p...

CVEs:CVE-2021-23841

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
Upstream advisory

CVE-2021-1757

iPadOSCoalition ESS 30-63%HIGH2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be ...

CVEs:CVE-2021-1757

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1818

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able t...

CVEs:CVE-2021-1818

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1758

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be...

CVEs:CVE-2021-1758

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1761

iPadOSCoalition ESS < 30%HIGH2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause a den...

CVEs:CVE-2021-1761

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1764

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may...

CVEs:CVE-2021-1764

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1792

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A remote attacker may be...

CVEs:CVE-2021-1792

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1799

iPadOSCoalition ESS < 30%MEDIUM2021-02-02

A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. A ma...

CVEs:CVE-2021-1799

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1772

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

A stack overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously cra...

CVEs:CVE-2021-1772

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1788

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Proces...

CVEs:CVE-2021-1788

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1759

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted ima...

CVEs:CVE-2021-1759

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2020-27937

macOSCoalition ESS < 30%MEDIUM2021-02-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to access private infor...

CVEs:CVE-2020-27937

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1763

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted USD file may lead t...

CVEs:CVE-2021-1763

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1791

watchOSCoalition ESS < 30%HIGH2021-02-02

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7...

CVEs:CVE-2021-1791

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1744

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a malicious...

CVEs:CVE-2021-1744

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1779

macOSCoalition ESS < 30%CRITICAL2021-02-02

A logic error in kext loading was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. An application may be able to execute arbitrary code with system pr...

CVEs:CVE-2021-1779

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1805

macOSCoalition ESS < 30%CRITICAL2021-02-10

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary...

CVEs:CVE-2021-1805

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1750

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. An application may be able to execute a...

CVEs:CVE-2021-1750

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1743

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously...

CVEs:CVE-2021-1743

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1745

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted USD file may l...

CVEs:CVE-2021-1745

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1762

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted USD file may ...

CVEs:CVE-2021-1762

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1746

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1746

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1776

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a mali...

CVEs:CVE-2021-1776

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-29633

macOSCoalition ESS < 30%HIGH2021-02-02

An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update ...

CVEs:CVE-2020-29633

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1754

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1754

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1783

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An access issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously cra...

CVEs:CVE-2021-1783

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1785

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciousl...

CVEs:CVE-2021-1785

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1774

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1774

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1777

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1777

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-10001

macOSCoalition ESS < 30%MEDIUM2021-02-02

An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory.

CVEs:CVE-2020-10001

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-29608

tvOSCoalition ESS < 30%MEDIUM2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security...

CVEs:CVE-2020-29608

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1741

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously...

CVEs:CVE-2021-1741

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1742

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1742

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1790

macOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted font may lead to arbitrary code execution.

CVEs:CVE-2021-1790

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1768

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted USD file may le...

CVEs:CVE-2021-1768

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1793

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1793

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1760

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious applica...

CVEs:CVE-2021-1760

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1737

macOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted image may lead to arbitrary code execut...

CVEs:CVE-2021-1737

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1738

macOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted image may lead to arbitrary code execut...

CVEs:CVE-2021-1738

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1753

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead ...

CVEs:CVE-2021-1753

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1806

macOSCoalition ESS < 30%CRITICAL2021-02-10

A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary code with...

CVEs:CVE-2021-1806

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1747

iPadOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing maliciously...

CVEs:CVE-2021-1747

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1775

macOSCoalition ESS < 30%CRITICAL2021-02-02

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted font may lead to arbitrary code execution.

CVEs:CVE-2021-1775

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1736

macOSCoalition ESS < 30%CRITICAL2021-02-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2021-1736

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1767

iPadOSCoalition ESS < 30%HIGH2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to heap corruption.

CVEs:CVE-2021-1767

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1766

iPadOSCoalition ESS < 30%HIGH2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1766

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1773

iPadOSCoalition ESS < 30%HIGH2021-02-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafte...

CVEs:CVE-2021-1773

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-29614

macOSCoalition ESS < 30%HIGH2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14...

CVEs:CVE-2020-29614

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2020-27945

macOSCoalition ESS < 30%CRITICAL2021-02-02

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. Processing maliciously crafted web content may lead t...

CVEs:CVE-2020-27945

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-27938

macOSCoalition ESS < 30%HIGH2021-02-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 M...

CVEs:CVE-2020-27938

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1771

macOSCoalition ESS < 30%MEDIUM2021-02-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A user that is removed from an iMessage group could rejoin the group.

CVEs:CVE-2021-1771

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1751

macOSCoalition ESS < 30%CRITICAL2021-02-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Mounting a maliciously crafted Samba network share may lead to arbitrary code exe...

CVEs:CVE-2021-1751

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1769

iPadOSCoalition ESS < 30%MEDIUM2021-02-02

A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious attacker with arbitrary r...

CVEs:CVE-2021-1769

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1797

iPadOSCoalition ESS < 30%MEDIUM2021-02-02

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to read a...

CVEs:CVE-2021-1797

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1786

iPadOSCoalition ESS < 30%MEDIUM2021-02-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local user may be able to cre...

CVEs:CVE-2021-1786

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1787

iPadOSCoalition ESS < 30%HIGH2021-02-02

Multiple issues were addressed with improved logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A local attacker may be able to elevate...

CVEs:CVE-2021-1787

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1802

macOSCoalition ESS < 30%HIGH2021-02-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. A local attacker may be able to elevate their privileges.

CVEs:CVE-2021-1802

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.