⚠ Actively exploited
Added to CISA KEV on 2022-05-04. Federal agencies required to patch by 2022-05-25. Required action: Apply updates per vendor instructions..

CVE-2021-1789Type Confusion in Apple IOS AND Ipados

Severity
8.8HIGHNVD
EPSS
0.2%
top 52.33%
CISA KEV
KEV
Added 2022-05-04
Due 2022-05-25
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedApr 2
KEV addedMay 4
KEV dueMay 25
Latest updateFeb 29
CISA Required Action: Apply updates per vendor instructions.

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

NVDapple/tvos< 14.4
CVEListV5apple/macosunspecified11.2+3
NVDapple/macos11.011.2
NVDapple/ipados< 14.4
NVDapple/watchos< 7.3

Also affects: Fedora 32, 33

🔴Vulnerability Details

4
GHSA
GHSA-c838-pj7m-89q4: A type confusion issue was addressed with improved state handling2022-05-24
CVEList
CVE-2021-1789: A type confusion issue was addressed with improved state handling2021-04-02
OSV
CVE-2021-1789: A type confusion issue was addressed with improved state handling2021-04-02
VulnCheck
Apple Multiple Products Type Confusion Vulnerability2021

📋Vendor Advisories

7
Red Hat
kernel: rtw88: Fix array overrun in rtw_get_tx_power_params()2024-02-29
CISA
Apple Multiple Products Type Confusion Vulnerability2022-05-04
Ubuntu
WebKitGTK vulnerabilities2021-03-29
Red Hat
webkitgtk: Type confusion issue leading to arbitrary code execution2021-03-22
Apple
CVE-2021-1789: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave2021-02-01

🕵️Threat Intelligence

2
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise2023-01-09
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise2023-01-09
CVE-2021-1789 — Type Confusion in Apple IOS AND Ipados | cvebase