CVE-2021-30663: Apple Multiple Products WebKit Integer Overflow Vulnerability
An integer overflow was addressed with improved input validation.
Other sources
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.36.4-1~deb10u1Fixed in 2.38.6-0+deb10u1Fixed in 2.40.5-1~deb11u1Fixed in 2.42.1-1~deb11u2Fixed in 2.40.5-1~deb12u1Fixed in 2.42.1-1~deb12u1Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1Fixed in 2.38.6-1Fixed in 2.42.1-1 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.3.1 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 14.6 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 14.1 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 14.1.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 12.5.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 14.5.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 14.5.1 - Upgrade
Upgrade
redhat/webkitgtkto a version that resolves this vulnerability.Fixed in 2.32.3 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.36.4-1~deb10u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.38.6-0+deb10u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.5-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-1~deb11u2 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.5-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.1-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30665
- CVE-2021-30663
- CVE-2021-30707
- CVE-2021-30685
- CVE-2021-30686
- CVE-2021-30753
- CVE-2021-30733
- CVE-2021-30727
- CVE-2021-30724
- CVE-2021-30771
- CVE-2021-30755
- CVE-2021-30697
- CVE-2021-30710
- CVE-2021-30687
- CVE-2021-30700
- CVE-2021-30701
- CVE-2021-30705
- CVE-2021-30706
- CVE-2021-30740
- CVE-2021-30704
- CVE-2021-30715
- CVE-2021-30736
- CVE-2021-30703
- CVE-2021-30677
- CVE-2021-30737
- CVE-2021-30744
- CVE-2021-21779
- CVE-2021-30682
- CVE-2021-30689
- CVE-2021-30749
- CVE-2021-30734
- CVE-2021-30720
- CVE-2021-23841
- CVE-2021-30698
- CVE-2021-30666
- CVE-2021-30661
Frequently Asked Questions
What is the vulnerability ID for this Apple product vulnerability?
The vulnerability ID for this Apple product vulnerability is CVE-2021-30663.
Which Apple products are affected by this vulnerability?
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit are affected by this vulnerability.
What is the severity of CVE-2021-30663?
The severity of CVE-2021-30663 is not specified in the provided information.
How can the CVE-2021-30663 vulnerability be exploited?
The CVE-2021-30663 vulnerability can be exploited by processing maliciously crafted web content.
How can I fix the CVE-2021-30663 vulnerability?
To fix the CVE-2021-30663 vulnerability, update to the recommended version provided by Apple.