cbcvebase.
CVE-2021-30758
published 2021-09-08

CVE-2021-30758: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

Affected

14 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < 14.714.7
appleios_14.7_and_ipados
appleiphone_os< 14.714.7
applemacos< 11.511.5
applemacos>= unspecified < 11.511.5
applemacos>= unspecified < 14.714.7
applemacos>= unspecified < 7.67.6
applemacos>= unspecified < 14.114.1
applesafari< 14.1.214.1.2
applesafari
appletvos< 14.714.7
applewatchos< 7.67.6
debianwebkit2gtk< webkit2gtk 2.32.2-1 (bookworm)webkit2gtk 2.32.2-1 (bookworm)
debianwpewebkit< webkit2gtk 2.32.2-1 (bookworm)webkit2gtk 2.32.2-1 (bookworm)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH