VDB
CVE-2021-1849
CVE-2021-1849
PUBLISHED
CVSS 7.5 HIGH
An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.
EPSS 0.15% · 36.0th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.15%
36.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | iphone_os | 0 |
| apple | ipados | 0 |
| Apple | tvOS | unspecified |
| Apple | macOS | unspecified |
| apple | macos | 11.0 |
| Apple | iOS and iPadOS | unspecified |
| apple | watchos | 0 |
| Apple | watchOS | * |
| apple | tvos | 0 |
Exploit Intelligence
Timeline
- Apr 27, 2021 CVE Published
- Sep 9, 2021 EPSS Score
- Sep 21, 2021 EPSS Score
- Nov 6, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 28, 2022 EPSS Score
- Jun 24, 2022 EPSS Score
- Oct 19, 2022 EPSS Score
- Dec 16, 2022 EPSS Score
References
- https://support.apple.com/fr-fr/HT212325 advisory
- https://support.apple.com/fr-fr/HT212327 advisory
- https://support.apple.com/fr-fr/HT212317 advisory
- https://support.apple.com/fr-fr/HT212318 advisory
- https://support.apple.com/fr-fr/HT212324 advisory
- https://support.apple.com/fr-fr/HT212326 advisory
- https://support.apple.com/fr-fr/HT212319 advisory
- https://support.apple.com/fr-fr/HT212323 advisory
- https://support.apple.com/fr-fr/HT212320 advisory
- https://support.apple.com/fr-fr/HT212321 advisory
- https://support.apple.com/en-us/HT212317 url
- https://support.apple.com/en-us/HT212323 url
- https://support.apple.com/en-us/HT212324 url
- https://support.apple.com/en-us/HT212325 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-1849 advisory