Apple Security Advisories · April 2021 — Apple Security Advisories
124 advisories 124 CVEs 2 EXPLOITED

Apple-vendor CVEs for 2021-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-30657

macOSExploitedCISA KEV listedMEDIUM2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been act...

CVEs:CVE-2021-30657

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-30661

iPadOSExploitedCISA KEV listedCRITICAL2021-04-27

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary...

CVEs:CVE-2021-30661

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-22945

OtherPoC exploitCRITICAL2021-04-13

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVEs:CVE-2021-22945

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2021-1748

iPadOSPoC exploitCRITICAL2021-04-02

A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

CVEs:CVE-2021-1748

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1883

iPadOSPoC exploitMEDIUM2021-04-27

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted server messag...

CVEs:CVE-2021-1883

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27935

iPadOSPoC exploitMEDIUM2021-04-02

Multiple issues were addressed with improved logic. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2020-27935

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27949

macOSPoC exploitHIGH2021-04-02

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may cause unexpected changes in memory...

CVEs:CVE-2020-27949

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9967

watchOSCoalition ESS 30-63%CRITICAL2021-04-02

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and i...

CVEs:CVE-2020-9967

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-30655

macOSCoalition ESS 30-63%HIGH2021-04-27

An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.

CVEs:CVE-2021-30655

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-30660

iPadOSCoalition ESS 30-63%HIGH2021-04-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to disclose kernel memory.

CVEs:CVE-2021-30660

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1810

macOSCoalition ESS 30-63%MEDIUM2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.

CVEs:CVE-2021-1810

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1834

macOSCoalition ESS < 30%HIGH2021-04-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to execute arbitrary code with ...

CVEs:CVE-2021-1834

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1829

macOSCoalition ESS < 30%HIGH2021-04-27

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2021-1829

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2021-1851

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to e...

CVEs:CVE-2021-1851

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1864

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.

CVEs:CVE-2021-1864

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1794

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

CVEs:CVE-2021-1794

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1795

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

CVEs:CVE-2021-1795

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1796

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.

CVEs:CVE-2021-1796

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1784

macOSCoalition ESS < 30%HIGH2021-04-27

A permissions issue existed in DiskArbitration. This was addressed with additional ownership checks. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to m...

CVEs:CVE-2021-1784

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1874

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2021-1874

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1817

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2021-1817

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1867

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5, macOS Big Sur 11.3. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2021-1867

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2021-1878

macOSCoalition ESS < 30%HIGH2021-04-27

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An attacker in a privileged network position may be able to leak sensitive ...

CVEs:CVE-2021-1878

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1809

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application m...

CVEs:CVE-2021-1809

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1808

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be abl...

CVEs:CVE-2021-1808

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1882

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to gain elevated privileges.

CVEs:CVE-2021-1882

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1811

watchOSCoalition ESS < 30%MEDIUM2021-04-26

A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS ...

CVEs:CVE-2021-1811

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1884

iPadOSCoalition ESS < 30%HIGH2021-04-27

A race condition was addressed with improved locking. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, Security Update 2021-003 Catalina, tvOS 14.5, macOS Big Sur 11.3. A remote attacker may be able to caus...

CVEs:CVE-2021-1884

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1816

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2021-1816

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1860

iPadOSCoalition ESS < 30%HIGH2021-04-27

A memory initialization issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious appl...

CVEs:CVE-2021-1860

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1881

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciousl...

CVEs:CVE-2021-1881

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1859

macOSCoalition ESS < 30%HIGH2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. Locked Notes content may have been unexpectedly unlocked.

CVEs:CVE-2021-1859

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2021-1825

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciousl...

CVEs:CVE-2021-1825

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
macos affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1820

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure of process m...

CVEs:CVE-2021-1820

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1843

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted image may l...

CVEs:CVE-2021-1843

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1841

macOSCoalition ESS < 30%CRITICAL2021-04-27

A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. An out-of-bounds write issue was addressed with improved bounds checking.

CVEs:CVE-2021-1841

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-27942

OtherCoalition ESS < 30%CRITICAL2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may lead to arbitrary code execution.

CVEs:CVE-2020-27942

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1876

macOSCoalition ESS < 30%CRITICAL2021-04-27

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing maliciously crafted web content may lead to arbitrary code e...

CVEs:CVE-2021-1876

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1873

macOSCoalition ESS < 30%MEDIUM2021-04-27

An API issue in Accessibility TCC permissions was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to unexpected...

CVEs:CVE-2021-1873

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-30659

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A validation issue was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. A malicious application may be able to leak sensitive user information.

CVEs:CVE-2021-30659

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1885

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2021-1885

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1857

watchOSCoalition ESS < 30%MEDIUM2021-04-27

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, ...

CVEs:CVE-2021-1857

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27920

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2....

CVEs:CVE-2020-27920

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1814

watchOSCoalition ESS < 30%CRITICAL2021-04-27

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2021-1814

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9962

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. Proces...

CVEs:CVE-2020-9962

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1826

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to universal cross site scripting.

CVEs:CVE-2021-1826

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1858

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

Processing a maliciously crafted image may lead to arbitrary code execution. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds write issue was addressed with...

CVEs:CVE-2021-1858

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-30653

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2021-30653

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9971

iPadOSCoalition ESS < 30%HIGH2021-04-02

A logic issue was addressed with improved validation. This issue is fixed in watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.0.1. A malicious application may be able to elevate privileges.

CVEs:CVE-2020-9971

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27941

macOSCoalition ESS < 30%CRITICAL2021-04-02

A validation issue was addressed with improved logic. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-27941

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-9975

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0....

CVEs:CVE-2020-9975

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1813

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be able t...

CVEs:CVE-2021-1813

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27914

macOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to execute ...

CVEs:CVE-2020-27914

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-27915

macOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to execute ...

CVEs:CVE-2020-27915

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9956

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. P...

CVEs:CVE-2020-9956

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27908

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. P...

CVEs:CVE-2020-27908

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-10015

macOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitra...

CVEs:CVE-2020-10015

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1847

macOSCoalition ESS < 30%CRITICAL2021-04-27

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Opening a maliciously crafted file may lead to unexpected application termi...

CVEs:CVE-2021-1847

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1740

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to ...

CVEs:CVE-2021-1740

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9960

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. P...

CVEs:CVE-2020-9960

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27923

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. ...

CVEs:CVE-2020-27923

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27924

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. P...

CVEs:CVE-2020-27924

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1872

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, macOS Big Sur 11.3. Muting a CallKit call while ringing may not result in mute being enabled.

CVEs:CVE-2021-1872

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
Upstream advisory

CVE-2020-27919

macOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. Processing a maliciously crafted image may lead to...

CVEs:CVE-2020-27919

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-29624

watchOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS ...

CVEs:CVE-2020-29624

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27947

macOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. An application may be able to execute arbitrary code with kernel priv...

CVEs:CVE-2020-27947

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9955

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.0.1. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2020-9955

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27922

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, watchOS 7.1, tvOS 14.2. Processin...

CVEs:CVE-2020-27922

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-29612

macOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to execute arbitrary code with ...

CVEs:CVE-2020-29612

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9926

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, iCloud for Windows 7.20, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-00...

CVEs:CVE-2020-9926

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1828

macOSCoalition ESS < 30%CRITICAL2021-04-27

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. An application may be able to cause unexpected system termination or write ...

CVEs:CVE-2021-1828

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-10008

macOSCoalition ESS < 30%MEDIUM2021-04-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.0.1. A malicious application with root privileges may be able to access private information.

CVEs:CVE-2020-10008

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-27933

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, iCloud for Windows 7.20, watchOS 6.2.8, tvOS 13.4.8, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-...

CVEs:CVE-2020-27933

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27931

iPadOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007...

CVEs:CVE-2020-27931

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27907

macOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary ...

CVEs:CVE-2020-27907

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2021-1880

watchOSCoalition ESS < 30%CRITICAL2021-04-27

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, watchOS 7.4. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2021-1880

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1831

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may allow shortcuts to access restricted files.

CVEs:CVE-2021-1831

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1849

iPadOSCoalition ESS < 30%HIGH2021-04-27

An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.

CVEs:CVE-2021-1849

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1832

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

Copied files may not have the expected file permissions. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. The issue was addressed with improved permissions logic.

CVEs:CVE-2021-1832

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1875

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A double free issue was addressed with improved memory management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously...

CVEs:CVE-2021-1875

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-29625

macOSCoalition ESS < 30%CRITICAL2021-04-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2020-29625

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-27939

macOSCoalition ESS < 30%CRITICAL2021-04-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2020-27939

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-27952

macOSCoalition ESS < 30%CRITICAL2021-04-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. Processing a maliciously crafted font file may lea...

CVEs:CVE-2020-27952

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1861

macOSCoalition ESS < 30%MEDIUM2021-04-27

An issue existed in determining cache occupancy. The issue was addressed through improved logic. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to track users by setting state in a cache.

CVEs:CVE-2021-1861

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2021-1846

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

Processing a maliciously crafted audio file may disclose restricted memory. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An out-of-bounds read was addressed with improve...

CVEs:CVE-2021-1846

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-30656

iPadOSCoalition ESS < 30%HIGH2021-04-27

An access issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to determine kernel memory layout.

CVEs:CVE-2021-30656

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2020-29616

macOSCoalition ESS < 30%CRITICAL2021-04-02

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. Processing a maliciously crafted image may lead to arbitrary code exe...

CVEs:CVE-2020-29616

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-30652

iPadOSCoalition ESS < 30%CRITICAL2021-04-27

A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A malicious application may be a...

CVEs:CVE-2021-30652

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27893

macOSCoalition ESS < 30%MEDIUM2021-04-02

An issue existed in screen sharing. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A user with screen sharing access may be able to view another user's screen.

CVEs:CVE-2020-27893

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-29610

iPadOSCoalition ESS < 30%MEDIUM2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciousl...

CVEs:CVE-2020-29610

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1855

macOSCoalition ESS < 30%CRITICAL2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A malicious website may be able to force unnecessary network connections to fetch its favicon.

CVEs:CVE-2021-1855

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-29615

iPadOSCoalition ESS < 30%HIGH2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciousl...

CVEs:CVE-2020-29615

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-27921

macOSCoalition ESS < 30%HIGH2021-04-02

A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with ...

CVEs:CVE-2020-27921

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1854

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .

CVEs:CVE-2021-1854

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2020-29639

iPadOSCoalition ESS < 30%MEDIUM2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted font may result in the disclosure of process memory.

CVEs:CVE-2020-29639

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2020-29620

macOSCoalition ESS < 30%HIGH2021-04-02

This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to elevate privileges.

CVEs:CVE-2020-29620

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1803

macOSCoalition ESS < 30%MEDIUM2021-04-02

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.0.1. A local application may be able to enumerate the user's iCloud documents.

CVEs:CVE-2021-1803

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-27901

macOSCoalition ESS < 30%MEDIUM2021-04-02

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restricti...

CVEs:CVE-2020-27901

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-9978

iPadOSCoalition ESS < 30%MEDIUM2021-04-02

This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An attack...

CVEs:CVE-2020-9978

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1865

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

An issue obscuring passwords in screenshots was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible on screen.

CVEs:CVE-2021-1865

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1837

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A certificate validation issue was addressed. This issue is fixed in iOS 14.5 and iPadOS 14.5. An attacker in a privileged network position may be able to alter network traffic.

CVEs:CVE-2021-1837

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1830

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

CVEs:CVE-2021-1830

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1815

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file ...

CVEs:CVE-2021-1815

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-30658

macOSCoalition ESS < 30%MEDIUM2021-04-27

This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Big Sur 11.3. A malicious application may bypass Gatekeeper checks.

CVEs:CVE-2021-30658

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-29621

macOSCoalition ESS < 30%MEDIUM2021-04-02

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to bypass Privacy preferences.

CVEs:CVE-2020-29621

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1739

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 1...

CVEs:CVE-2021-1739

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-29623

iPadOSCoalition ESS < 30%LOW2021-04-02

"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tv...

CVEs:CVE-2020-29623

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2021-1840

macOSCoalition ESS < 30%HIGH2021-04-27

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.

CVEs:CVE-2021-1840

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1756

iPadOSCoalition ESS < 30%LOW2021-04-02

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker with physical access to a device may be able to see private contact...

CVEs:CVE-2021-1756

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1807

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4. A local user may be able to write arbitrary files.

CVEs:CVE-2021-1807

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1835

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.

CVEs:CVE-2021-1835

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2020-27936

macOSCoalition ESS < 30%HIGH2021-04-02

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A local u...

CVEs:CVE-2020-27936

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1824

macOSCoalition ESS < 30%MEDIUM2021-04-27

This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application with root privileges may be able to access private information.

CVEs:CVE-2021-1824

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1822

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to modify protected parts of the file system.

CVEs:CVE-2021-1822

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1839

macOSCoalition ESS < 30%HIGH2021-04-27

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A local attacker may be able to elevate their privileges.

CVEs:CVE-2021-1839

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2021-1853

macOSCoalition ESS < 30%HIGH2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. A local attacker may be able to elevate their privileges.

CVEs:CVE-2021-1853

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2021-1836

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 14.5 and iPadOS 14.5, tvOS 14.5. A local user may be able to create or modify privileged files.

CVEs:CVE-2021-1836

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2021-1852

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

CVEs:CVE-2021-1852

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1877

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

CVEs:CVE-2021-1877

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2021-1755

macOSCoalition ESS < 30%LOW2021-04-02

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A person with physical access to an iOS device may be able to access contacts from ...

CVEs:CVE-2021-1755

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple — —
Upstream advisory

CVE-2020-27899

iPadOSCoalition ESS < 30%HIGH2021-04-02

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1, watchOS 7.1, tvOS 14.2. A local attacker may be able to elevate their privileges.

CVEs:CVE-2020-27899

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1868

iPadOSCoalition ESS < 30%HIGH2021-04-27

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local attacker may be able to...

CVEs:CVE-2021-1868

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
macos affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2021-1848

iPadOSCoalition ESS < 30%MEDIUM2021-04-27

The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.

CVEs:CVE-2021-1848

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
Upstream advisory

CVE-2020-9930

macOSCoalition ESS < 30%HIGH2021-04-02

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. A local user may be able to cause unexpected system termination or...

CVEs:CVE-2020-9930

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.