CVE-2021-30919: Apple macOS CoreGraphics PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CoreGraphics. An out-of-bounds write was addressed with improved input validation.
Other sources
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30876
- CVE-2021-30879
- CVE-2021-30877
- CVE-2021-30880
- CVE-2021-30907
- CVE-2021-30899
- CVE-2021-30926
- CVE-2021-30917
- CVE-2021-30903
- CVE-2021-30905
- CVE-2021-30919
- CVE-2021-30881
- CVE-2021-30900
- CVE-2021-30906
- CVE-2021-30824
- CVE-2021-30901
- CVE-2021-30922
- CVE-2021-30821
- CVE-2021-30883
- CVE-2021-30909
- CVE-2021-30916
- CVE-2021-30910
- CVE-2021-30911
- CVE-2021-30844
- CVE-2021-30868
- CVE-2021-30913
- CVE-2021-30912
- CVE-2021-30915
- CVE-2021-30908
- CVE-2021-30833
- CVE-2021-30892
- CVE-2021-31007
- CVE-2021-30895
- CVE-2021-30896
- CVE-2021-30894
- CVE-2021-30924
- CVE-2021-30886
- CVE-2021-31008
- CVE-2021-30887
- CVE-2021-30888
- CVE-2021-30889
- CVE-2021-30890
- CVE-2021-30873
- CVE-2021-30834
- CVE-2021-30994
- CVE-2021-30931
- CVE-2021-30866
- CVE-2020-9846
- CVE-2021-30923
- CVE-2021-30831
- CVE-2021-30840
- CVE-2021-30852
- CVE-2021-30933
- CVE-2021-30867
- CVE-2021-30814
- CVE-2021-30864
- CVE-2021-30813
- CVE-2021-31011
- CVE-2021-30904
- CVE-2021-30874
- CVE-2021-30808
- CVE-2021-30920
- CVE-2021-31004
- CVE-2021-31002
- CVE-2021-31005
- CVE-2021-30897
- CVE-2021-30884
- CVE-2021-30818
- CVE-2021-30836
- CVE-2021-30846
- CVE-2021-30849
- CVE-2021-30848
- CVE-2021-30851
- CVE-2021-30809
- CVE-2021-30823
- CVE-2021-30861
- CVE-2021-30930
- CVE-2021-30918
- CVE-2021-30902
- CVE-2021-30914
- CVE-2021-30875
Frequently Asked Questions
What is CVE-2021-30919?
CVE-2021-30919 is a vulnerability in CoreGraphics that allows an attacker to perform an out-of-bounds write through improved input validation.
Who is affected by CVE-2021-30919?
CVE-2021-30919 affects Apple Catalina, Apple macOS Big Sur, Apple iOS, Apple iPadOS, Apple macOS Monterey, Apple iOS, Apple iPadOS, Apple tvOS, and Apple watchOS.
How can I fix CVE-2021-30919?
To fix CVE-2021-30919, update to the recommended versions of Apple Catalina, Apple macOS Big Sur, Apple iOS, Apple iPadOS, Apple macOS Monterey, Apple iOS, Apple iPadOS, Apple tvOS, and Apple watchOS.
What is the severity of CVE-2021-30919?
The severity of CVE-2021-30919 is not specified in the provided information.
Where can I find more information about CVE-2021-30919?
More information about CVE-2021-30919 can be found at the following references: [Link 1](https://support.apple.com/en-us/HT212867), [Link 2](https://support.apple.com/en-us/HT212871), [Link 3](https://support.apple.com/en-us/HT212874).