CERT-In Vulnerability Note
CIVN-2021-0352
Multiple Vulnerabilities in Apple Products
Original Issue Date:December 14, 2021
Severity Rating: HIGH
Software Affected
- iOS and iPadOS prior to 15.2
- macOS Monterey prior to 12.1
- macOS Big Sur prior to 11.6.2
- macOS Catalina prior to security update 2021-008
- watchOS prior to 8.3
- tvOS prior to 15.2
Overview
Multiple Vulnerabilities have been reported in Apple products which could be exploited by an attacker to gain elevated privileges, bypass security restriction, execute arbitrary code and disclose sensitive infor-mation on the targeted system.
Description
Multiple Vulnerabilities exists in Apple products due to improper memory handling, state management, input validation, checks, handling of file metadata, state handling, bounds checking, locking, sandbox restrictions, access restrictions, permissions logic, execution of JavaScript in a scripting dictionary and mis-configuration in Bluetooth. An attacker could exploit these vulnerabilities by convincing the user to run a maliciously crafted application.
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges, bypass security restriction, execute arbitrary code and disclose sensitive information on the targeted system.
Solution
Apply appropriate updates as mentioned in the Apple Security Updates:
https://support.apple.com/en-us/HT212976
https://support.apple.com/en-us/HT212978
https://support.apple.com/en-us/HT212979
https://support.apple.com/en-us/HT212981
https://support.apple.com/en-us/HT212980
https://support.apple.com/en-us/HT212975
Vendor Information
Apple
https://support.apple.com/en-us/HT212976
https://support.apple.com/en-us/HT212978
https://support.apple.com/en-us/HT212979
https://support.apple.com/en-us/HT212981
https://support.apple.com/en-us/HT212980
https://support.apple.com/en-us/HT212975
References
Apple
https://support.apple.com/en-us/HT212976
https://support.apple.com/en-us/HT212978
https://support.apple.com/en-us/HT212979
https://support.apple.com/en-us/HT212981
https://support.apple.com/en-us/HT212980
https://support.apple.com/en-us/HT212975
CVE Name
CVE-2021-30767
CVE-2021-30916
CVE-2021-30926
CVE-2021-30927
CVE-2021-30929
CVE-2021-30931
CVE-2021-30932
CVE-2021-30934
CVE-2021-30935
CVE-2021-30936
CVE-2021-30937
CVE-2021-30938
CVE-2021-30939
CVE-2021-30940
CVE-2021-30941
CVE-2021-30942
CVE-2021-30945
CVE-2021-30946
CVE-2021-30947
CVE-2021-30948
CVE-2021-30949
CVE-2021-30950
CVE-2021-30951
CVE-2021-30952
CVE-2021-30953
CVE-2021-30954
CVE-2021-30955
CVE-2021-30957
CVE-2021-30958
CVE-2021-30959
CVE-2021-30960
CVE-2021-30961
CVE-2021-30963
CVE-2021-30964
CVE-2021-30965
CVE-2021-30966
CVE-2021-30967
CVE-2021-30968
CVE-2021-30969
CVE-2021-30970
CVE-2021-30971
CVE-2021-30973
CVE-2021-30975
CVE-2021-30976
CVE-2021-30977
CVE-2021-30979
CVE-2021-30980
CVE-2021-30981
CVE-2021-30982
CVE-2021-30983
CVE-2021-30984
CVE-2021-30985
CVE-2021-30986
CVE-2021-30987
CVE-2021-30988
CVE-2021-30990
CVE-2021-30991
CVE-2021-30992
CVE-2021-30993
CVE-2021-30995
CVE-2021-30996
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|