CVE-2021-30905: Apple macOS AudioCodecs LOAS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
CoreAudio. An out-of-bounds read was addressed with improved bounds checking.
Other sources
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina. Processing a maliciously crafted file may disclose user information.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the Deserialize function in AudioCodecs. Crafted data in a LOAS file can trigger a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30876
- CVE-2021-30879
- CVE-2021-30877
- CVE-2021-30880
- CVE-2021-30907
- CVE-2021-30899
- CVE-2021-30926
- CVE-2021-30917
- CVE-2021-30903
- CVE-2021-30905
- CVE-2021-30919
- CVE-2021-30881
- CVE-2021-30900
- CVE-2021-30906
- CVE-2021-30824
- CVE-2021-30901
- CVE-2021-30922
- CVE-2021-30821
- CVE-2021-30883
- CVE-2021-30909
- CVE-2021-30916
- CVE-2021-30910
- CVE-2021-30911
- CVE-2021-30844
- CVE-2021-30868
- CVE-2021-30913
- CVE-2021-30912
- CVE-2021-30915
- CVE-2021-30908
- CVE-2021-30833
- CVE-2021-30892
- CVE-2021-31007
- CVE-2021-30895
- CVE-2021-30896
- CVE-2021-30894
- CVE-2021-30924
- CVE-2021-30886
- CVE-2021-31008
- CVE-2021-30887
- CVE-2021-30888
- CVE-2021-30889
- CVE-2021-30890
- CVE-2021-30873
- CVE-2021-30834
- CVE-2021-30994
- CVE-2021-30931
- CVE-2021-30866
- CVE-2020-9846
- CVE-2021-30923
- CVE-2021-30831
- CVE-2021-30840
- CVE-2021-30852
- CVE-2021-30933
- CVE-2021-30867
- CVE-2021-30814
- CVE-2021-30864
- CVE-2021-30813
- CVE-2021-31011
- CVE-2021-30904
- CVE-2021-30874
- CVE-2021-30808
- CVE-2021-30920
- CVE-2021-31004
- CVE-2021-31002
- CVE-2021-31005
- CVE-2021-30897
- CVE-2021-30884
- CVE-2021-30818
- CVE-2021-30836
- CVE-2021-30846
- CVE-2021-30849
- CVE-2021-30848
- CVE-2021-30851
- CVE-2021-30809
- CVE-2021-30823
- CVE-2021-30861
- CVE-2021-30930
- CVE-2021-30838
- CVE-2021-30820
- CVE-2021-30928
- CVE-2021-30860
- CVE-2021-31010
- CVE-2021-30841
- CVE-2021-30843
- CVE-2021-30842
- CVE-2021-30847
- CVE-2021-30857
- CVE-2021-30859
- CVE-2013-0340
- CVE-2021-30855
- CVE-2021-30826
- CVE-2021-30858
- CVE-2021-30914
- CVE-2021-30875
- CVE-2021-30902
Frequently Asked Questions
What is the vulnerability CVE-2021-30905?
CVE-2021-30905 is a vulnerability in CoreAudio that allows an out-of-bounds read.
What software is affected by CVE-2021-30905?
The vulnerability affects Apple Catalina, macOS Big Sur (up to version 11.6.1), macOS Monterey (up to version 12.0.1), iOS (up to version 15.1), iPadOS (up to version 15.1), watchOS (up to version 8.1), and tvOS (up to version 15.1).
How can I fix CVE-2021-30905?
To fix CVE-2021-30905, update your Apple device to the latest available version, including macOS Catalina 10.15.7, macOS Big Sur 11.6.1, macOS Monterey 12.0.1, iOS 15.1, iPadOS 15.1, watchOS 8.1, and tvOS 15.1.
Where can I find more information about CVE-2021-30905?
You can find more information about CVE-2021-30905 on the Apple support page: https://support.apple.com/en-us/HT212867
Are there any related references for CVE-2021-30905?
Yes, you can find related references for CVE-2021-30905 on the following Apple support pages: https://support.apple.com/en-us/HT212867, https://support.apple.com/en-us/HT212871, https://support.apple.com/en-us/HT212874