CVE-2021-30860
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
- Affected products
- Alt Linux, Apple Macos, Ios, Ipados, Macos Big Sur, Watchos
- Apple Ipados
- < 14.8
- Apple Iphone Os
- < 12.5.5, 14.8
- Apple Mac Os X
- < 10.15.7
- Apple Macos
- < 11.6
- Apple Watchos
- < 7.6.2
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 76.0% (99th percentile)
- Weakness
- CWE-190
- NVD status
- Analyzed
- Published
- 2021-08-24
CVE-2021-30860 at NVD
5 known exploits for CVE-2021-30860
Proof-of-concept code and exploit modules indexed by Sploitus