Apple Security Advisories · June 2021 — Apple Security Advisories
4 advisories 4 CVEs 2 EXPLOITED

Apple-vendor CVEs for 2021-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-30762

iOSExploitedCISA KEV listedCRITICAL2021-06-15

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively ...

CVEs:CVE-2021-30762

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2021-30761

iOSExploitedCISA KEV listedCRITICAL2021-06-15

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been activel...

CVEs:CVE-2021-30761

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2009-0947

OtherEPSS <= 49%CRITICAL2021-06-02

Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.

CVEs:CVE-2009-0947

Affected products

ProductStatusVendorPackageEcosystem
files affected apple
Upstream advisory

CVE-2009-0948

OtherEPSS <= 49%CRITICAL2021-06-02

Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.

CVEs:CVE-2009-0948

Affected products

ProductStatusVendorPackageEcosystem
files affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.