CVE-2021-30763Improper Input Validation in Apple Watchos

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 64.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 24

Description

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.7, watchOS 7.6. A shortcut may be able to bypass Internet permission requirements.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5apple/watchosunspecified7.6
NVDapple/watchos< 7.6
CVEListV5apple/iosunspecified14.7
NVDapple/ipados< 14.7
NVDapple/iphone_os< 14.7

🔴Vulnerability Details

2
GHSA
GHSA-hhhm-592j-2r47: An input validation issue was addressed with improved input validation2022-05-24
CVEList
CVE-2021-30763: An input validation issue was addressed with improved input validation2021-09-08

📋Vendor Advisories

1
Apple
CVE-2021-30763: iOS 14.7 and iPadOS 14.7
CVE-2021-30763 — Improper Input Validation in Apple | cvebase