Macos Apple Macos

Do you want an email whenever new security vulnerabilities are reported in Apple Macos?

Recent Apple Macos Security Advisories

Advisory Title Published
HT213257 macOS Monterey 12.4 Security Content May 16, 2022
HT213256 macOS Big Sur 11.6.6 Security Content May 16, 2022
HT213220 macOS Monterey 12.3.1 Security Content March 31, 2022
HT213183 macOS Monterey 12.3 Security Content March 14, 2022
HT213184 macOS Big Sur 11.6.5 Security Content March 14, 2022
HT213092 macOS Monterey 12.2.1 Security Content February 10, 2022
HT213055 macOS Big Sur 11.6.3 Security Content January 26, 2022
HT213054 macOS Monterey 12.2 Security Content January 26, 2022
HT212979 macOS Big Sur 11.6.2 Security Content December 13, 2021
HT212978 macOS Monterey 12.1 Security Content December 13, 2021

By the Year

In 2022 there have been 52 vulnerabilities in Apple Macos with an average score of 7.1 out of ten. Last year Macos had 444 security vulnerabilities published. Right now, Macos is on track to have less security vulnerabilities in 2022 than it did last year. However, the average CVE base score of the vulnerabilities in 2022 is greater by 0.06.

Year Vulnerabilities Average Score
2022 52 7.11
2021 444 7.05
2020 36 6.97
2019 0 0.00
2018 0 0.00

It may take a day or so for new Macos vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple Macos Security Vulnerabilities

A validation issue was addressed with improved input sanitization

CVE-2022-22589 6.1 - Medium - March 18, 2022

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javascript.

Improper Input Validation

A cross-origin issue in the IndexDB API was addressed with improved input validation

CVE-2022-22594 6.5 - Medium - March 18, 2022

A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

Origin Validation Error

Description: A permissions issue was addressed with improved validation

CVE-2022-22599 2.4 - Low - March 18, 2022

Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.

Incorrect Permission Assignment for Critical Resource

A logic issue was addressed with improved state management

CVE-2022-22617 7.8 - High - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to gain elevated privileges.

Improper Privilege Management

An out-of-bounds read was addressed with improved input validation

CVE-2022-22625 7.1 - High - March 18, 2022

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.

Out-of-bounds Read

An out-of-bounds read was addressed with improved bounds checking

CVE-2022-22626 7.1 - High - March 18, 2022

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.

Out-of-bounds Read

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22631 7.8 - High - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to gain elevated privileges.

Memory Corruption

A memory corruption issue was addressed with improved memory handling

CVE-2022-22591 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A buffer overflow issue was addressed with improved memory handling

CVE-2022-22593 7.8 - High - March 18, 2022

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be able to execute arbitrary code with kernel privileges.

Classic Buffer Overflow

A use after free issue was addressed with improved memory management

CVE-2022-22620 8.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Dangling pointer

An out-of-bounds read was addressed with improved bounds checking

CVE-2022-22627 7.1 - High - March 18, 2022

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.

Memory Corruption

A memory corruption issue was addressed with improved state management

CVE-2022-22633 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.

Memory Corruption

A logic issue was addressed with improved state management

CVE-2022-22639 7.8 - High - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

Improper Privilege Management

A memory initialization issue was addressed with improved memory handling

CVE-2022-22657 7.8 - High - March 18, 2022

A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

Improper Initialization

An out-of-bounds write was addressed with improved input validation

CVE-2021-30771 7.8 - High - March 18, 2022

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, iOS 14.6 and iPadOS 14.6, watchOS 7.5, tvOS 14.6. Processing a maliciously crafted font file may lead to arbitrary code execution.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-22590 8.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A logic issue was addressed with improved state management

CVE-2022-22592 6.5 - Medium - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

A memory corruption issue was addressed with improved validation

CVE-2022-22597 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted file may lead to arbitrary code execution.

Memory Corruption

An out-of-bounds read was addressed with improved bounds checking

CVE-2022-22664 7.8 - High - March 18, 2022

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

Out-of-bounds Read

A privacy issue existed in the handling of Contact cards

CVE-2022-22644 5.5 - Medium - March 18, 2022

A privacy issue existed in the handling of Contact cards. This was addressed with improved state management. This issue is fixed in macOS Monterey 12.3. A malicious application may be able to access information about a user's contacts.

A use after free issue was addressed with improved memory management

CVE-2022-22615 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

This issue was addressed with improved checks

CVE-2022-22621 4.6 - Medium - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A person with physical access to an iOS device may be able to see sensitive information via keyboard suggestions.

Information Disclosure

A logic issue was addressed with improved state management

CVE-2022-22632 9.8 - Critical - March 18, 2022

A logic issue was addressed with improved state management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, watchOS 8.5, macOS Monterey 12.3. A malicious application may be able to elevate privileges.

A null pointer dereference was addressed with improved validation

CVE-2022-22638 6.5 - Medium - March 18, 2022

A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a denial of service attack.

NULL Pointer Dereference

A memory corruption issue was addressed with improved validation

CVE-2022-22640 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. An application may be able to execute arbitrary code with kernel privileges.

Buffer Overflow

This issue was addressed with improved checks

CVE-2022-22647 4.6 - Medium - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A person with access to a Mac may be able to bypass Login Window.

This issue was addressed with improved checks

CVE-2022-22648 5.5 - Medium - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to read restricted memory.

This issue was addressed with improved checks

CVE-2022-22650 5.5 - Medium - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A plug-in may be able to inherit the application's permissions and access user data.

Improper Preservation of Permissions

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22651 7.5 - High - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.3. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

Memory Corruption

An out-of-bounds read was addressed with improved input validation

CVE-2022-22611 7.8 - High - March 18, 2022

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to arbitrary code execution.

Out-of-bounds Read

A memory consumption issue was addressed with improved memory handling

CVE-2022-22612 7.8 - High - March 18, 2022

A memory consumption issue was addressed with improved memory handling. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, iTunes 12.12.3 for Windows, watchOS 8.5, macOS Monterey 12.3. Processing a maliciously crafted image may lead to heap corruption.

Buffer Overflow

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22613 7.8 - High - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A use after free issue was addressed with improved memory management

CVE-2022-22614 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

A use after free issue was addressed with improved memory management

CVE-2022-22641 9.8 - Critical - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

Dangling pointer

An authentication issue was addressed with improved state management

CVE-2022-22656 3.3 - Low - March 18, 2022

An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in users desktop from the fast user switching screen.

authentification

This issue was addressed with a new entitlement

CVE-2022-22660 5.5 - Medium - March 18, 2022

This issue was addressed with a new entitlement. This issue is fixed in macOS Monterey 12.3. An app may be able to spoof system notifications and UI.

Improper Input Validation

A type confusion issue was addressed with improved state handling

CVE-2022-22661 7.8 - High - March 18, 2022

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to execute arbitrary code with kernel privileges.

Object Type Confusion

A logic issue was addressed with improved validation

CVE-2022-22665 7.8 - High - March 18, 2022

A logic issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.3. A malicious application may be able to gain root privileges.

Improper Privilege Management

The issue was addressed with additional permissions checks

CVE-2022-22609 7.5 - High - March 18, 2022

The issue was addressed with additional permissions checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to read other applications' settings.

This issue was addressed with improved checks

CVE-2022-22643 7.5 - High - March 18, 2022

This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A user may send audio and video in a FaceTime call without knowing that they have done so.

A use after free issue was addressed with improved memory management

CVE-2022-22669 7.8 - High - March 18, 2022

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

Dangling pointer

The issue was addressed with improved permissions logic

CVE-2022-22600 5.5 - Medium - March 18, 2022

The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. A malicious application may be able to bypass certain Privacy preferences.

A logic issue was addressed with improved validation

CVE-2022-22578 7.8 - High - March 18, 2022

A logic issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. A malicious application may be able to gain root privileges.

Improper Privilege Management

An information disclosure issue was addressed with improved state management

CVE-2022-22579 7.8 - High - March 18, 2022

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution.

Exposure of Resource to Wrong Sphere

A permissions issue was addressed with improved validation

CVE-2022-22583 5.5 - Medium - March 18, 2022

A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access restricted files.

Exposure of Resource to Wrong Sphere

A memory corruption issue was addressed with improved validation

CVE-2022-22584 7.8 - High - March 18, 2022

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.

Memory Corruption

An issue existed within the path validation logic for symlinks

CVE-2022-22585 7.5 - High - March 18, 2022

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access a user's files.

insecure temporary file

An out-of-bounds write issue was addressed with improved bounds checking

CVE-2022-22586 9.8 - Critical - March 18, 2022

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A memory corruption issue was addressed with improved input validation

CVE-2022-22587 9.8 - Critical - March 18, 2022

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

Memory Corruption

vim is vulnerable to Use After Free

CVE-2022-0156 5.5 - Medium - January 10, 2022

vim is vulnerable to Use After Free

Dangling pointer

vim is vulnerable to Heap-based Buffer Overflow

CVE-2022-0158 3.3 - Low - January 10, 2022

vim is vulnerable to Heap-based Buffer Overflow

Heap-based Buffer Overflow

vim is vulnerable to Out-of-bounds Read

CVE-2022-0128 7.8 - High - January 06, 2022

vim is vulnerable to Out-of-bounds Read

Out-of-bounds Read

vim is vulnerable to Out-of-bounds Read

CVE-2021-4193 5.5 - Medium - December 31, 2021

vim is vulnerable to Out-of-bounds Read

Out-of-bounds Read

vim is vulnerable to Use After Free

CVE-2021-4192 7.8 - High - December 31, 2021

vim is vulnerable to Use After Free

Dangling pointer

vim is vulnerable to Use After Free

CVE-2021-4187 7.8 - High - December 29, 2021

vim is vulnerable to Use After Free

Dangling pointer

vim is vulnerable to Use After Free

CVE-2021-4173 7.8 - High - December 27, 2021

vim is vulnerable to Use After Free

Dangling pointer

vim is vulnerable to Out-of-bounds Read

CVE-2021-4166 7.1 - High - December 25, 2021

vim is vulnerable to Out-of-bounds Read

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30767 5.5 - Medium - December 23, 2021

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A local user may be able to modify protected parts of the file system.

An issue existed in the handling of Contact sharing

CVE-2017-13892 7.5 - High - December 23, 2021

An issue existed in the handling of Contact sharing. This issue was addressed with improved handling of user information. This issue is fixed in macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan. Sharing contact information may lead to unexpected data sharing.

A race condition was addressed with additional validation

CVE-2017-13905 8.1 - High - December 23, 2021

A race condition was addressed with additional validation. This issue is fixed in tvOS 11.2, iOS 11.2, macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan, watchOS 4.2. An application may be able to gain elevated privileges.

Race Condition

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-4136 7.8 - High - December 19, 2021

vim is vulnerable to Heap-based Buffer Overflow

Memory Corruption

An out-of-bounds read was addressed with improved input validation

CVE-2021-30836 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted audio file may disclose restricted memory.

Out-of-bounds Read

A logic issue was addressed with improved state management

CVE-2021-30834 7.8 - High - October 28, 2021

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, Security Update 2021-007 Catalina. Processing a malicious audio file may result in unexpected application termination or arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30808 5.5 - Medium - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A malicious application may be able to modify protected parts of the file system.

A use after free issue was addressed with improved memory management

CVE-2021-30809 8.8 - High - October 28, 2021

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

Dangling pointer

A memory corruption issue was addressed with improved input validation

CVE-2021-30814 7.8 - High - October 28, 2021

A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.

Memory Corruption

A type confusion issue was addressed with improved state handling

CVE-2021-30818 8.8 - High - October 28, 2021

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Object Type Confusion

This issue was addressed with improved checks

CVE-2021-30833 5.5 - Medium - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.

A memory corruption issue was addressed with improved state management

CVE-2021-30824 7.8 - High - October 28, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A permissions issue was addressed with improved validation

CVE-2021-30817 5.5 - Medium - October 28, 2021

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access data about the accounts the user is using Family Sharing with.

An out-of-bounds read was addressed with improved input validation

CVE-2021-30831 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted font may result in the disclosure of process memory.

Out-of-bounds Read

This issue was addressed with improved checks

CVE-2021-30840 7.8 - High - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30813 6.5 - Medium - October 28, 2021

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. A person with access to a host Mac may be able to bypass the Login Window in Remote Desktop for a locked instance of macOS.

A resource exhaustion issue was addressed with improved input validation

CVE-2020-10005 6.5 - Medium - October 28, 2021

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. An attacker in a privileged network position may be able to perform denial of service.

Resource Exhaustion

An out-of-bounds read was addressed with improved input validation

CVE-2020-29629 5.5 - Medium - October 28, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to read restricted memory.

Out-of-bounds Read

An out-of-bounds write was addressed with improved input validation

CVE-2020-9897 7.8 - High - October 28, 2021

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.

Memory Corruption

A logic issue was addressed with improved state management

CVE-2021-1821 6.5 - Medium - October 28, 2021

A logic issue was addressed with improved state management. This issue is fixed in watchOS 7.6, macOS Big Sur 11.5. Visiting a maliciously crafted webpage may lead to a system denial of service.

A logic issue was addressed with improved restrictions

CVE-2021-30823 6.5 - Medium - October 28, 2021

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30821 7.8 - High - October 28, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30848 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.

Memory Corruption

This issue was addressed with improved checks

CVE-2021-30811 5.5 - Medium - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker may be able to read sensitive information.

An out-of-bounds read was addressed with improved input validation

CVE-2021-30819 5.5 - Medium - October 19, 2021

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Processing a maliciously crafted USD file may disclose memory contents.

Out-of-bounds Read

This issue was addressed with improved checks

CVE-2021-30835 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, iTunes 12.12 for Windows, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted image may lead to arbitrary code execution.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30838 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to execute arbitrary code with system privileges on devices with an Apple Neural Engine.

This issue was addressed with improved checks

CVE-2021-30847 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in watchOS 8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing a maliciously crafted image may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30841 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2021-30842 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

A memory corruption issue was addressed with improved memory handling

CVE-2021-30846 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A URI parsing issue was addressed with improved parsing

CVE-2021-30829 7.8 - High - October 19, 2021

A URI parsing issue was addressed with improved parsing. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local user may be able to execute arbitrary files.

This issue was addressed with improved checks

CVE-2021-30828 5.5 - Medium - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local user may be able to read arbitrary files as root.

Exposure of Resource to Wrong Sphere

A memory corruption issue was addressed with improved memory handling

CVE-2021-30830 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A malicious application may be able to execute arbitrary code with kernel privileges.

Memory Corruption

A memory corruption issue was addressed with improved state management

CVE-2021-30832 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges.

Memory Corruption

A logic issue was addressed with improved state management

CVE-2021-30844 7.5 - High - October 19, 2021

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory.

Memory Leak

An out-of-bounds read was addressed with improved bounds checking

CVE-2021-30845 5.5 - Medium - October 19, 2021

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6. A local user may be able to read kernel memory.

Out-of-bounds Read

A memory corruption issue was addressed with improved memory handling

CVE-2021-30807 7.8 - High - October 19, 2021

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

An access issue was addressed with improved access restrictions

CVE-2021-30850 5.5 - Medium - October 19, 2021

An access issue was addressed with improved access restrictions. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6, tvOS 15. A user may gain access to protected parts of the file system.

Exposure of Resource to Wrong Sphere

This issue was addressed with improved checks

CVE-2021-30843 7.8 - High - October 19, 2021

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

Multiple memory corruption issues were addressed with improved memory handling

CVE-2021-30849 7.8 - High - October 19, 2021

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.

Memory Corruption

A permissions issue existed

CVE-2021-30827 7.8 - High - October 19, 2021

A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges.

Improper Preservation of Permissions

A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP

CVE-2021-22946 7.5 - High - September 29, 2021

A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.

Cleartext Transmission of Sensitive Information

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Siemens Sinec Infrastructure Network Services or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple Macos
Product

subscribe