Apple Security Advisories · September 2021 — Apple Security Advisories
40 advisories 40 CVEs

Apple-vendor CVEs for 2021-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2021-22946

OtherPoC exploitHIGH2021-09-14

A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This re...

CVEs:CVE-2021-22946

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2021-39537

OtherPoC exploitCRITICAL2021-09-20

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

CVEs:CVE-2021-39537

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2021-22947

OtherPoC exploitMEDIUM2021-09-14

When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not fl...

CVEs:CVE-2021-22947

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2021-30849

iPadOSPoC exploitCRITICAL2021-09-20

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content m...

CVEs:CVE-2021-30849

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30846

iPadOSPoC exploitCRITICAL2021-09-20

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2021-30846

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30848

iPadOSPoC exploitCRITICAL2021-09-21

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.

CVEs:CVE-2021-30848

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2021-30837

iPadOSCoalition ESS 30-63%HIGH2021-09-21

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2021-30837

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
Upstream advisory

CVE-2021-30835

iPadOSCoalition ESS < 30%CRITICAL2021-09-20

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2021-30835

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30847

iPadOSCoalition ESS < 30%CRITICAL2021-09-20

This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrar...

CVEs:CVE-2021-30847

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30755

watchOSCoalition ESS < 30%MEDIUM2021-09-08

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5. An out-of-bounds read was addressed with improved input validation.

CVEs:CVE-2021-30755

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30841

iPadOSCoalition ESS < 30%CRITICAL2021-09-20

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arb...

CVEs:CVE-2021-30841

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30842

iPadOSCoalition ESS < 30%CRITICAL2021-09-20

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arb...

CVEs:CVE-2021-30842

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30843

iPadOSCoalition ESS < 30%CRITICAL2021-09-20

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arb...

CVEs:CVE-2021-30843

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30826

iPadOSCoalition ESS < 30%HIGH2021-09-21

A logic issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. In certain situations, the baseband would fail to enable integrity and ciphering protection.

CVEs:CVE-2021-30826

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-30752

iPadOSCoalition ESS < 30%CRITICAL2021-09-08

Processing a maliciously crafted image may lead to arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An out-of-bounds read was addressed with improved input validation.

CVEs:CVE-2021-30752

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30764

iPadOSCoalition ESS < 30%CRITICAL2021-09-08

Processing a maliciously crafted file may lead to arbitrary code execution. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. This issue was addressed with improved checks.

CVEs:CVE-2021-30764

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30838

iPadOSCoalition ESS < 30%HIGH2021-09-21

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to execute arbitrary code with system privileges on devices with an Apple Neural Engine.

CVEs:CVE-2021-30838

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2021-30742

iPadOSCoalition ESS < 30%CRITICAL2021-09-08

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVEs:CVE-2021-30742

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-30664

iPadOSCoalition ESS < 30%CRITICAL2021-09-08

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2021-30664

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30753

iPadOSCoalition ESS < 30%MEDIUM2021-09-08

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVEs:CVE-2021-30753

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30850

tvOSCoalition ESS < 30%HIGH2021-09-21

An access issue was addressed with improved access restrictions. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6, tvOS 15. A user may gain access to protected parts of the file system.

CVEs:CVE-2021-30850

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2021-30662

iPadOSCoalition ESS < 30%CRITICAL2021-09-08

This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted file may lead to arbitrary code execution.

CVEs:CVE-2021-30662

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-30750

macOSCoalition ESS < 30%MEDIUM2021-09-08

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.

CVEs:CVE-2021-30750

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2021-30757

OtherCoalition ESS < 30%MEDIUM2021-09-08

This issue was addressed by enabling hardened runtime. This issue is fixed in iMovie 10.2.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.

CVEs:CVE-2021-30757

Affected products

ProductStatusVendorPackageEcosystem
imovie affected apple
Upstream advisory

CVE-2021-30706

iPadOSCoalition ESS < 30%MEDIUM2021-09-08

Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.

CVEs:CVE-2021-30706

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30819

iPadOSCoalition ESS < 30%MEDIUM2021-09-21

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Processing a maliciously crafted USD file may disclose memory contents.

CVEs:CVE-2021-30819

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2021-30751

macOSCoalition ESS < 30%MEDIUM2021-09-08

This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass certain Privacy preferences.

CVEs:CVE-2021-30751

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2021-30825

iPadOSCoalition ESS < 30%HIGH2021-09-21

This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to cause unexpected application termination or arbitrary code execution.

CVEs:CVE-2021-30825

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-30810

iPadOSCoalition ESS < 30%CRITICAL2021-09-21

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8, tvOS 15. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.

CVEs:CVE-2021-30810

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-30756

iPadOSCoalition ESS < 30%MEDIUM2021-09-08

A local attacker may be able to view Now Playing information from the lock screen. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6. A privacy issue in Now Playing was addressed with improved permissions.

CVEs:CVE-2021-30756

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2021-30811

iPadOSCoalition ESS < 30%MEDIUM2021-09-21

This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker may be able to read sensitive information.

CVEs:CVE-2021-30811

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2021-30815

iPadOSCoalition ESS < 30%LOW2021-09-21

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A local attacker may be able to view contacts from the lock screen.

CVEs:CVE-2021-30815

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-30654

OtherCoalition ESS < 30%MEDIUM2021-09-08

This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information.

CVEs:CVE-2021-30654

Affected products

ProductStatusVendorPackageEcosystem
garageband affected apple
Upstream advisory

CVE-2021-1770

iPadOSEPSS <= 49%CRITICAL2021-09-08

A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management.

CVEs:CVE-2021-1770

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2021-1812

iPadOSEPSS <= 49%HIGH2021-09-08

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A malicious application may be able to execute arbitrary code with system privileges.

CVEs:CVE-2021-1812

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-1838

iPadOSEPSS <= 49%CRITICAL2021-09-08

This issue was addressed with improved checks. This issue is fixed in iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2021-1838

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-1833

iPadOSEPSS <= 49%HIGH2021-09-08

This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may be able to gain elevated privileges.

CVEs:CVE-2021-1833

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-27940

tvOSEPSS <= 49%MEDIUM2021-09-08

This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app.

CVEs:CVE-2020-27940

Affected products

ProductStatusVendorPackageEcosystem
apple_tv affected apple
Upstream advisory

CVE-2021-1862

iPadOSEPSS <= 49%LOW2021-09-08

Description: A person with physical access may be able to access contacts. This issue is fixed in iOS 14.5 and iPadOS 14.5. Impact: An issue with Siri search access to information was addressed with improved logic.

CVEs:CVE-2021-1862

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2021-1863

iPadOSEPSS <= 49%LOW2021-09-08

An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place p...

CVEs:CVE-2021-1863

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.