CVE-2021-30760: Input Validation
ActionKit. An input validation issue was addressed with improved input validation.
Other sources
AMD Kernel. A memory corruption issue was addressed with improved input validation.
— Apple
An integer overflow was addressed through improved input validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, Security Update 2021-005 Mojave, Security Update 2021-004 Catalina. Processing a maliciously crafted font file may lead to arbitrary code execution.
— MITRE
Analytics. A logic issue was addressed with improved restrictions.
— Apple
Analytics. This issue was addressed with a new entitlement.
— Apple
App Store. A permissions issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30805
- CVE-2021-30871
- CVE-2021-30790
- CVE-2021-31006
- CVE-2021-30781
- CVE-2021-30748
- CVE-2021-30775
- CVE-2021-30776
- CVE-2021-30786
- CVE-2021-30772
- CVE-2021-30783
- CVE-2021-30777
- CVE-2021-30789
- CVE-2021-30774
- CVE-2021-30780
- CVE-2021-30768
- CVE-2021-30817
- CVE-2021-30804
- CVE-2021-30760
- CVE-2021-30788
- CVE-2021-30759
- CVE-2021-30803
- CVE-2021-30779
- CVE-2021-30785
- CVE-2021-30787
- CVE-2021-30766
- CVE-2021-30765
- CVE-2021-30784
- CVE-2021-30793
- CVE-2021-30778
- CVE-2021-30677
- CVE-2021-3518
- CVE-2021-30796
- CVE-2021-30792
- CVE-2021-30791
- CVE-2021-1821
- CVE-2021-30782
- CVE-2021-31004
- CVE-2021-30798
- CVE-2021-30758
- CVE-2021-30795
- CVE-2021-30797
- CVE-2021-30799
- CVE-2021-30773
- CVE-2021-30802
- CVE-2021-30769
- CVE-2021-30770
- CVE-2021-30811
- CVE-2021-30672
- CVE-2021-30733
- CVE-2021-30731
- CVE-2021-30703
- CVE-2021-30763
- CVE-2018-25010
- CVE-2018-25011
- CVE-2018-25014
- CVE-2020-36328
- CVE-2020-36329
- CVE-2020-36330
- CVE-2020-36331
- CVE-2021-30800
Frequently Asked Questions
What is CVE-2021-30760?
CVE-2021-30760 is a vulnerability in the FontParser component that allows for integer overflow due to inadequate input validation.
Which software is affected by CVE-2021-30760?
CVE-2021-30760 affects multiple versions of Apple software including Mojave, watchOS, tvOS, Catalina, and macOS Big Sur.
How does CVE-2021-30760 impact the affected software?
CVE-2021-30760 can result in an integer overflow, which could potentially lead to arbitrary code execution or other security issues.
How can I fix CVE-2021-30760?
To fix CVE-2021-30760, it is recommended to update to the latest version of the affected Apple software, as the vulnerability has been addressed through improved input validation.
Where can I find more information about CVE-2021-30760?
For more information about CVE-2021-30760, you can refer to the following Apple support articles: [https://support.apple.com/en-us/HT212605](https://support.apple.com/en-us/HT212605), [https://support.apple.com/en-us/HT212604](https://support.apple.com/en-us/HT212604), [https://support.apple.com/en-us/HT212600](https://support.apple.com/en-us/HT212600).