CVE-2021-1776
Published Jan 26, 2021
·Updated
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted font file may lead to arbitrary code execution.
Credit
Ivan Fratric(Google Project Zero)
Affected Software
30 affected componentsFixes available
Apple tvOS<14.4
14.4
Apple macOS Big Sur<11.2
11.2
Apple Catalina
Apple Mojave
Apple WatchOS<7.3
7.3
Apple iOS<14.4
14.4
Apple iPadOS<14.4
14.4
Apple iPadOS<14.4
Apple iPhone OS<14.4
Apple iOS and macOS>=10.14<10.14.6
Apple iOS and macOS>=10.15<10.15.7
Apple iOS and macOS=10.14.6
Apple iOS and macOS=10.14.6-security_update_2019-004
Apple iOS and macOS=10.14.6-security_update_2019-005
Apple iOS and macOS=10.14.6-security_update_2019-006
Apple iOS and macOS=10.14.6-security_update_2019-007
Apple iOS and macOS=10.14.6-security_update_2020-001
Apple iOS and macOS=10.14.6-security_update_2020-002
Apple iOS and macOS=10.14.6-security_update_2020-003
Apple iOS and macOS=10.14.6-security_update_2020-004
Apple iOS and macOS=10.14.6-security_update_2020-005
Apple iOS and macOS=10.14.6-security_update_2020-006
Apple iOS and macOS=10.14.6-security_update_2020-007
Apple iOS and macOS=10.14.6-supplemental_update
Apple iOS and macOS=10.14.6-supplemental_update_2
Apple iOS and macOS=10.15.7
Apple iOS and macOS=10.15.7-supplemental_update
Apple macOS>=11.0<11.2
Apple tvOS<14.4
Apple WatchOS<7.3
Event History
Apr 2, 2021
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-1776.
2
What is the affected software?
The affected software includes macOS Big Sur, Catalina, Mojave, watchOS, iOS, iPadOS, and tvOS.
3
What is the severity of CVE-2021-1776?
The severity of CVE-2021-1776 is not specified.
4
How do I fix CVE-2021-1776?
To fix CVE-2021-1776, it is recommended to update to the latest version of the affected software.
5
Where can I find more information about CVE-2021-1776?
You can find more information about CVE-2021-1776 on the Apple support website.