CVE-2021-30663
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products WebKit Integer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 4% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-190
מוצרים מושפעים
apple: safari; apple: ipados; apple: iphone os; apple: macos; apple: tvos
קישורים
- https://support.apple.com/en-us/HT212335 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212336 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212341 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212532 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212534 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212335 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212336 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212341 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212532 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212534 Release NotesVendor Advisory