CERT-In Vulnerability Note
CIVN-2021-0179
Memory Corruption vulnerability in Apple iOS 14.7.1 and iPadOS 14.7.1 security updates
Original Issue Date:July 28, 2021
Severity Rating: HIGH
Software Affected
- Apple macOS Big Sur versions prior to 11.5.1
- Apple iOS and iPadOS versions prior to 14.7.1
- iPhone 6s and later,
- iPad Pro (all models)
- iPad Air 2 and later
- iPad 5th generation and later
- iPad mini 4 and later
- iPod touch (7th generation)
- macOS Big Sur
Overview
A vulnerability has been reported in Apple iOS and iPadOS which could be exploited by a remote attacker to execute arbitrary code and gain elevated privileges on a targeted system.
Description
This vulnerability exists in IOMobileFrameBuffer of Apple iOS and iPadOS due to memory corruption issue with inadequate memory handling. A remote attacker with kernel privileges can exploit this vulnerability using a maliciously crafted application.
Successful exploitation of these vulnerabilities could allow an attacker to with kernel privileges to execute arbitrary code and gain elevated privileges on a targeted system.
Note: This vulnerability is currently being exploited in the wild, users are advised to apply patches urgently.
Solution
Apply appropriate updates as mentioned in Apple Security updates:
https://support.apple.com/en-us/HT212622
https://support.apple.com/en-us/HT212623
Vendor Information
Apple
https://support.apple.com/en-us/HT212622
https://support.apple.com/en-us/HT212623
References
Apple
https://support.apple.com/en-us/HT212622
https://support.apple.com/en-us/HT212623
CVE Name
CVE-2021-30807
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|