CVE-2021-1859
published 2021-09-08CVE-2021-1859: A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. Locked Notes content may have been unexpectedly unlocked.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.41%
69.5th percentile
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. Locked Notes content may have been unexpectedly unlocked.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | >= 11.0 < 11.3 | 11.3 |
| apple | macos | >= unspecified < 11.3 | 11.3 |
| apple | macos_big_sur | — | — |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-1859
vendor_chrome·2022-05-31·CVSS 9.8
CVE-2022-1859 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-1859
Long Term Support Channel Update for ChromeOS
CVE-2022-1859: Use after free in Performance Manager. 1297283 High CVE-2022-1636: Use after free in Performance APIs 1278608 High CVE-2021-43527 [internally reported] 1304660 High CVE-2022-23308 CrOS: Vulnerability reported in dev-libs/libxml2 1315563 Medium CVE-2022-1867: Insufficient validation of untrusted input in Data Transfer
Severity: high
Apple
CVE-2021-1859: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 7.5
CVE-2021-1859 [HIGH] CVE-2021-1859: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2021-1859
Component: Notes
Impact: Locked Notes content may have been unexpectedly unlocked
Description: A logic issue was addressed with improved state management.
GHSA
GHSA-w647-5772-8rc2: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2021-1859 [HIGH] GHSA-w647-5772-8rc2: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3. Locked Notes content may have been unexpectedly unlocked.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-08
Published