cbcvebase.
CVE-2021-30942
published 2021-08-24

CVE-2021-30942: Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur…

PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.52%
71.9th percentile
Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing a maliciously crafted image may lead to arbitrary code execution.

Affected

19 ranges
VendorProductVersion rangeFixed in
appleios_and_ipados>= unspecified < 15.215.2
appleipados< 15.215.2
appleiphone_os< 15.215.2
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.6.211.6.2
applemacos>= 12.0 < 12.112.1
applemacos>= unspecified < 12.112.1
applemacos>= unspecified < 11.611.6
applemacos>= unspecified < 15.215.2
applemacos>= unspecified < 20212021
applemacos_big_sur
applemacos_monterey
applesecurity_update_2021-008_catalina
appletvos< 15.215.2
appletvos
applewatchos< 8.38.3
applewatchos
applewatchos>= unspecified < 8.38.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.