CVE-2021-30758
published 2021-09-08CVE-2021-30758: A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < 14.7 | 14.7 |
| apple | ios_14.7_and_ipados | — | — |
| apple | iphone_os | < 14.7 | 14.7 |
| apple | macos | < 11.5 | 11.5 |
| apple | macos | >= unspecified < 11.5 | 11.5 |
| apple | macos | >= unspecified < 14.7 | 14.7 |
| apple | macos | >= unspecified < 7.6 | 7.6 |
| apple | macos | >= unspecified < 14.1 | 14.1 |
| apple | safari | < 14.1.2 | 14.1.2 |
| apple | safari | — | — |
| apple | tvos | < 14.7 | 14.7 |
| apple | watchos | < 7.6 | 7.6 |
| debian | webkit2gtk | < webkit2gtk 2.32.2-1 (bookworm) | webkit2gtk 2.32.2-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.32.2-1 (bookworm) | webkit2gtk 2.32.2-1 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH