CVE-2021-30952: Apple Multiple Products Integer Overflow or Wraparound Vulnerability
A flaw was found in WebKitGTK. An integer overflow was addressed with improved input validation.
Reference: https://webkitgtk.org/security/WSA-2022-0001.html
Other sources
An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution.
— CISA
WebKit. An integer overflow was addressed with improved input validation.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.36.4-1~deb10u1Fixed in 2.38.6-0+deb10u1Fixed in 2.40.5-1~deb11u1Fixed in 2.42.1-1~deb11u2Fixed in 2.40.5-1~deb12u1Fixed in 2.42.1-1~deb12u1Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1Fixed in 2.38.6-1Fixed in 2.42.1-1 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 15.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 8.3 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.1 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 15.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.2 - Upgrade
Upgrade
redhat/webkitgtkto a version that resolves this vulnerability.Fixed in 2.32.4 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.36.4-1~deb10u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.38.6-0+deb10u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.5-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-1~deb11u2 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.5-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1~deb11u1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.38.6-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.1-1 - Compensating control
Apply mitigations per vendor instructions; for cloud services follow applicable BOD 22-01 guidance; if mitigations are unavailable, discontinue use of the affected product until a vendor-provided fix is applied.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30960
- CVE-2021-30966
- CVE-2021-30926
- CVE-2021-30942
- CVE-2021-30962
- CVE-2021-30957
- CVE-2021-30958
- CVE-2021-30945
- CVE-2021-31013
- CVE-2021-31000
- CVE-2021-30939
- CVE-2021-30916
- CVE-2021-30937
- CVE-2021-30927
- CVE-2021-30980
- CVE-2021-30949
- CVE-2021-30993
- CVE-2021-30955
- CVE-2021-30995
- CVE-2021-30968
- CVE-2021-30947
- CVE-2021-30944
- CVE-2021-30934
- CVE-2021-30936
- CVE-2021-30951
- CVE-2021-30952
- CVE-2021-30984
- CVE-2021-30953
- CVE-2021-30954
- CVE-2021-30943
- CVE-2021-30946
- CVE-2021-30767
- CVE-2021-30964
- CVE-2021-30987
- CVE-2021-30950
- CVE-2021-30986
- CVE-2021-30935
- CVE-2021-31007
- CVE-2021-30977
- CVE-2021-30981
- CVE-2021-30996
- CVE-2021-30982
- CVE-2021-30976
- CVE-2021-30990
- CVE-2021-31009
- CVE-2021-30971
- CVE-2021-30973
- CVE-2021-30929
- CVE-2021-30979
- CVE-2021-30940
- CVE-2021-30941
- CVE-2021-30975
- CVE-2021-30972
- CVE-2021-30970
- CVE-2021-30965
- CVE-2021-30938
- CVE-2021-30956
- CVE-2021-30992
- CVE-2021-30983
- CVE-2021-30985
- CVE-2021-30991
- CVE-2021-30998
- CVE-2021-30997
- CVE-2021-30967
- CVE-2021-30988
- CVE-2021-30932
- CVE-2021-30948
Frequently Asked Questions
What is CVE-2021-30952?
CVE-2021-30952 is a vulnerability in WebKit where an integer overflow was addressed with improved input validation.
Which software versions are affected by CVE-2021-30952?
CVE-2021-30952 affects macOS Monterey 12.1, Safari 15.2, iOS 15.2, iPadOS 15.2, watchOS 8.3, and tvOS 15.2.
How can I fix CVE-2021-30952?
To fix CVE-2021-30952, update your software to the latest available version provided by Apple.
Where can I find more information about CVE-2021-30952?
You can find more information about CVE-2021-30952 on the Apple security advisory page linked in the references.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-30952?
CVE-2021-30952 is associated with CWE-20 and CWE-190.