CVE-2021-1857
published 2021-09-08CVE-2021-1857: A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.22%
65.4th percentile
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 12.3 | 12.3 |
| apple | icloud_for_windows | >= unspecified < 12.3 | 12.3 |
| apple | ios_14.5_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.5 | 14.5 |
| apple | ipados | < 14.5 | 14.5 |
| apple | iphone_os | < 14.5 | 14.5 |
| apple | itunes | < 12.11.3 | 12.11.3 |
| apple | itunes_for_windows | >= unspecified < 12.11 | 12.11 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | macos | >= 11.0 < 11.3 | 11.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-1856
vendor_chrome·2022-05-24·CVSS 8.8
CVE-2022-1856 [HIGH] Stable Channel Update for Desktop: CVE-2022-1856
Stable Channel Update for Desktop
CVE-2022-1856: Use after free in User Education. Reported by Nan Wang(@eternalsakura13) and Guang Gong of 360 Alpha Lab on 2022-05-06 [$2000][ 1227995 ] High CVE-2022-1857: Insufficient policy enforcement in File System API
Reported by Daniel Rhea on 2021-07-11 [$1000][ 1314310 ] High CVE-2022-1858: Out of bounds read in DevTools
Severity: high
Apple
CVE-2021-1857: iOS 14.5 and iPadOS 14.5
vendor_apple·2021-04-26·CVSS 6.5
CVE-2021-1857 [MEDIUM] CVE-2021-1857: iOS 14.5 and iPadOS 14.5
Apple Security Update: About the security content of iOS 14.5 and iPadOS 14.5
Product: iOS 14.5 and iPadOS
Version: 14.5
CVE: CVE-2021-1857
Component: CFNetwork
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A memory initialization issue was addressed with improved memory handling.
Apple
CVE-2021-1857: Security Update 2021-002 Catalina
vendor_apple·2021-04-26·CVSS 6.5
CVE-2021-1857 [MEDIUM] CVE-2021-1857: Security Update 2021-002 Catalina
Apple Security Update: About the security content of Security Update 2021-002 Catalina
Product: Security Update 2021-002 Catalina
CVE: CVE-2021-1857
Component: CFNetwork
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A memory initialization issue was addressed with improved memory handling.
Apple
CVE-2021-1857: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 6.5
CVE-2021-1857 [MEDIUM] CVE-2021-1857: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2021-1857
Component: CFNetwork
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A memory initialization issue was addressed with improved memory handling.
GHSA
GHSA-gr6c-576g-h3q2: A memory initialization issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2021-1857 [MEDIUM] CWE-665 GHSA-gr6c-576g-h3q2: A memory initialization issue was addressed with improved memory handling
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT212317https://support.apple.com/en-us/HT212319https://support.apple.com/en-us/HT212321https://support.apple.com/en-us/HT212323https://support.apple.com/en-us/HT212324https://support.apple.com/en-us/HT212325https://support.apple.com/en-us/HT212326https://support.apple.com/en-us/HT212327https://support.apple.com/en-us/HT212317https://support.apple.com/en-us/HT212319https://support.apple.com/en-us/HT212321https://support.apple.com/en-us/HT212323https://support.apple.com/en-us/HT212324https://support.apple.com/en-us/HT212325https://support.apple.com/en-us/HT212326https://support.apple.com/en-us/HT212327
2021-09-08
Published