CVE-2021-1873
published 2021-09-08CVE-2021-1873: An API issue in Accessibility TCC permissions was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.24%
65.8th percentile
An API issue in Accessibility TCC permissions was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to unexpectedly leak a user's credentials from secure text fields.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.14 – 10.14.5 | — |
| apple | mac_os_x | 10.15 – 10.15.5 | — |
| apple | macos | >= 11.0 < 11.3 | 11.3 |
| apple | macos | >= unspecified < 11.3 | 11.3 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-002_catalina | — | — |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2022-1873
vendor_chrome·2022-05-24·CVSS 6.5
CVE-2022-1873 [LOW] Stable Channel Update for Desktop: CVE-2022-1873
Stable Channel Update for Desktop
CVE-2022-1873: Insufficient policy enforcement in COOP. Reported by NDevTK on 2022-03-11 [$500][ 1251588 ] Low CVE-2022-1874: Insufficient policy enforcement in Safe Browsing
Reported by hjy79425575 on 2021-09-21 [$500][ 1306443 ] Low CVE-2022-1875: Inappropriate implementation in PDF
Severity: low
Apple
CVE-2021-1873: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 6.5
CVE-2021-1873 [MEDIUM] CVE-2021-1873: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2021-1873
Component: WindowServer
Impact: A malicious application may be able to unexpectedly leak a user's credentials from secure text fields
Description: An API issue in Accessibility TCC permissions was addressed with improved state management.
Apple
CVE-2021-1873: Security Update 2021-002 Catalina
vendor_apple·2021-04-26·CVSS 6.5
CVE-2021-1873 [MEDIUM] CVE-2021-1873: Security Update 2021-002 Catalina
Apple Security Update: About the security content of Security Update 2021-002 Catalina
Product: Security Update 2021-002 Catalina
CVE: CVE-2021-1873
Component: WindowServer
Impact: A malicious application may be able to unexpectedly leak a user's credentials from secure text fields
Description: An API issue in Accessibility TCC permissions was addressed with improved state management.
GHSA
GHSA-5fv4-524x-62xf: An API issue in Accessibility TCC permissions was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2021-1873 [MEDIUM] CWE-522 GHSA-5fv4-524x-62xf: An API issue in Accessibility TCC permissions was addressed with improved state management
An API issue in Accessibility TCC permissions was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to unexpectedly leak a user's credentials from secure text fields.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-08
Published