CERT-In Advisory
CIAD-2021-0035
Multiple vulnerabilities in Apple Products
Original Issue Date: September 22, 2021
Severity Rating: High
Software Affected
- Apple iOS and iPadOS versions prior to 15
- iPhone 6s and later,
- iPad Pro (all models),
- iPad Air 2 and later,
- iPad 5th generation and later,
- iPad mini 4 and later,
- iPod touch (7th generation)
- Apple Safari versions prior to 15
- Apple tvOS versions prior to 15
- Apple watchOS versions prior to 8
- Apple iTunes versions prior to 12.12 for Windows
- Apple Xcode versions prior to 13
Overview
Multiple vulnerabilities have been reported in the Apple products which could be exploited by a remote attacker to cause denial of service conditions, gain elevated privileges, execute arbitrary code, access sensitive information, bypass security restrictions and spoofing on the targeted device.
Description
These vulnerabilities exist in Apple products due to memory corruption issues, race condition, out-of-bounds read, authorization issues and input validation issues.
Successful exploitation of these vulnerabilities could allow a remote attacker to cause denial of service conditions, gain elevated privileges, execute arbitrary code, access sensitive information, bypass security restrictions and spoofing on the targeted system.
Solution
Apply appropriate updates as mentioned in Apple Security updates:
https://support.apple.com/en-us/HT212814
https://support.apple.com/en-us/HT212815
https://support.apple.com/en-us/HT212816
https://support.apple.com/en-us/HT212817
https://support.apple.com/en-us/HT212818
https://support.apple.com/en-us/HT212819
Vendor Information
Apple
https://support.apple.com/en-us/HT212814
https://support.apple.com/en-us/HT212815
https://support.apple.com/en-us/HT212816
https://support.apple.com/en-us/HT212817
https://support.apple.com/en-us/HT212818
https://support.apple.com/en-us/HT212819
References
Apple
https://support.apple.com/en-us/HT212814
https://support.apple.com/en-us/HT212815
https://support.apple.com/en-us/HT212816
https://support.apple.com/en-us/HT212817
https://support.apple.com/en-us/HT212818
https://support.apple.com/en-us/HT212819
CVE Name
CVE-2013-0340
CVE-2016-0742
CVE-2016-0746
CVE-2016-0747
CVE-2017-7529
CVE-2018-16843
CVE-2018-16844
CVE-2018-16845
CVE-2019-20372
CVE-2021-30810
CVE-2021-30811
CVE-2021-30815
CVE-2021-30819
CVE-2021-30825
CVE-2021-30826
CVE-2021-30835
CVE-2021-30837
CVE-2021-30838
CVE-2021-30841
CVE-2021-30842
CVE-2021-30843
CVE-2021-30846
CVE-2021-30847
CVE-2021-30848
CVE-2021-30849
CVE-2021-30850
CVE-2021-30851
CVE-2021-30854
CVE-2021-30855
CVE-2021-30857
CVE-2021-30863
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|