CVE-2021-1849Improper Verification of Cryptographic Signature in Apple IOS AND Ipados

Severity
7.5HIGHNVD
EPSS
0.2%
top 63.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 24

Description

An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A malicious application may be able to bypass Privacy preferences.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages11 packages

CVEListV5apple/tvosunspecified14.5
NVDapple/tvos< 14.5
CVEListV5apple/macosunspecified11.3
NVDapple/macos11.011.3
NVDapple/ipados< 14.5

🔴Vulnerability Details

1
GHSA
GHSA-ww3h-g64f-837r: An issue in code signature validation was addressed with improved checks2022-05-24

📋Vendor Advisories

2
Apple
CVE-2021-1849: iOS 14.5 and iPadOS 14.52021-04-26
Apple
CVE-2021-1849: macOS Big Sur 11.32021-04-26

💬Community

1
Bugzilla
CVE-2020-15103 freerdp: integer overflow due to missing input sanitation in rdpegfx channel2020-07-20