CVE-2021-30926: Input Validation
ColorSync. A memory corruption issue in the processing of ICC profiles was addressed with improved input validation.
Other sources
ColorSync. Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation.
Description: A memory corruption issue in the processing of ICC profiles was addressed with improved input validation. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS 15.2, tvOS 15.2. Processing a maliciously crafted image may lead to arbitrary code execution.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30876
- CVE-2021-30879
- CVE-2021-30877
- CVE-2021-30880
- CVE-2021-30907
- CVE-2021-30899
- CVE-2021-30926
- CVE-2021-30917
- CVE-2021-30903
- CVE-2021-30905
- CVE-2021-30919
- CVE-2021-30881
- CVE-2021-30900
- CVE-2021-30906
- CVE-2021-30824
- CVE-2021-30901
- CVE-2021-30922
- CVE-2021-30821
- CVE-2021-30883
- CVE-2021-30909
- CVE-2021-30916
- CVE-2021-30910
- CVE-2021-30911
- CVE-2021-30844
- CVE-2021-30868
- CVE-2021-30913
- CVE-2021-30912
- CVE-2021-30915
- CVE-2021-30908
- CVE-2021-30833
- CVE-2021-30892
- CVE-2021-30960
- CVE-2021-30966
- CVE-2021-30942
- CVE-2021-30962
- CVE-2021-30957
- CVE-2021-30958
- CVE-2021-30945
- CVE-2021-31013
- CVE-2021-31000
- CVE-2021-30939
- CVE-2021-30937
- CVE-2021-30927
- CVE-2021-30980
- CVE-2021-30949
- CVE-2021-30993
- CVE-2021-30955
- CVE-2021-30995
- CVE-2021-30968
- CVE-2021-30947
- CVE-2021-30944
- CVE-2021-30934
- CVE-2021-30936
- CVE-2021-30951
- CVE-2021-30952
- CVE-2021-30984
- CVE-2021-30953
- CVE-2021-30954
- CVE-2021-30873
- CVE-2021-30834
- CVE-2021-30943
- CVE-2021-30946
- CVE-2021-30767
- CVE-2021-30964
- CVE-2021-30987
- CVE-2021-30950
- CVE-2021-30986
- CVE-2021-30935
- CVE-2021-31007
- CVE-2021-30977
- CVE-2021-30981
- CVE-2021-30996
- CVE-2021-30982
- CVE-2021-30976
- CVE-2021-30990
- CVE-2021-31009
- CVE-2021-30971
- CVE-2021-30973
- CVE-2021-30929
- CVE-2021-30979
- CVE-2021-30940
- CVE-2021-30941
- CVE-2021-30975
- CVE-2021-30972
- CVE-2021-30970
- CVE-2021-30965
- CVE-2021-30938
- CVE-2021-30918
- CVE-2021-30902
- CVE-2021-30888
- CVE-2021-30956
- CVE-2021-30992
- CVE-2021-30983
- CVE-2021-30985
- CVE-2021-30991
- CVE-2021-30998
- CVE-2021-30997
- CVE-2021-30967
- CVE-2021-30988
- CVE-2021-30932
- CVE-2021-30948
Frequently Asked Questions
What is CVE-2021-30926?
CVE-2021-30926 is a memory corruption issue in the processing of ICC profiles in ColorSync.
Which software versions are affected by CVE-2021-30926?
CVE-2021-30926 affects Apple Catalina, Apple macOS Big Sur (up to version 11.6.1), Apple macOS Monterey (up to version 12.1), Apple iOS (up to version 14.8.1), Apple iPadOS (up to version 14.8.1), Apple iOS (up to version 15.2), Apple iPadOS (up to version 15.2), Apple watchOS (up to version 8.3), and Apple tvOS (up to version 15.2).
How can I fix CVE-2021-30926?
To fix CVE-2021-30926, update your software to the versions specified by Apple.
Where can I find more information about CVE-2021-30926?
You can find more information about CVE-2021-30926 on the following Apple support pages: [Link 1](https://support.apple.com/en-us/HT212978), [Link 2](https://support.apple.com/en-us/HT212980), [Link 3](https://support.apple.com/en-us/HT212871).
What is the CWE classification for CVE-2021-30926?
CVE-2021-30926 is classified under CWE-20 (Improper Input Validation).