CVE-2021-1820Improper Initialization in Apple IOS AND Ipados

Severity
6.5MEDIUMNVD
EPSS
0.8%
top 26.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 24

Description

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure of process memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages13 packages

CVEListV5apple/tvosunspecified14.5
NVDapple/tvos< 14.5
CVEListV5apple/macosunspecified11.3
NVDapple/macos11.011.3
NVDapple/ipados< 14.5

🔴Vulnerability Details

2
GHSA
GHSA-g25v-ch2q-jp7c: A memory initialization issue was addressed with improved memory handling2022-05-24
OSV
CVE-2021-1820: A memory initialization issue was addressed with improved memory handling2021-09-08

📋Vendor Advisories

4
Red Hat
webkitgtk: Memory initialization issue possibly leading to memory disclosure2021-07-28
Apple
CVE-2021-1820: iOS 14.5 and iPadOS 14.52021-04-26
Apple
CVE-2021-1820: macOS Big Sur 11.32021-04-26
Debian
CVE-2021-1820: webkit2gtk - A memory initialization issue was addressed with improved memory handling. This ...2021