CVE-2021-30758

high

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

References

https://support.apple.com/en-us/HT212606

https://support.apple.com/en-us/HT212604

https://support.apple.com/en-us/HT212605

https://support.apple.com/en-us/HT212602

https://support.apple.com/en-us/HT212601

Details

Source: MITRE

Published: 2021-09-08

Updated: 2021-09-14

Type: CWE-843

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH