QID 375421

Date Published: 2021-04-07

QID 375421: Apple Safari Arbitrary Code Execution Vulnerability(HT212223)

Safari is a Web-browser developed by Apple which is based on the WebKit engine.

Affected Versions:
Apple safari 14.0.3 prior build number 14610.4.3.1.7 on macOS Mojave and 15610.4.3.1.7 on macOS Catalina.

Fixed versions:
The build number for Safari 14.0.3 is 14610.4.3.1.7 on macOS Mojave and 15610.4.3.1.7 on macOS Catalina.

QID Detection Logic (Authenticated)
This checks for vulnerable versions of Apple Safari

Processing maliciously crafted web content may lead to arbitrary code execution

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    The apple browser safari need to be upgrade to latest build number for Safari 14.0.3 is 14610.4.3.1.7 on macOS Mojave and 15610.4.3.1.7 on macOS Catalina.
    For more information regarding the update HT212223.
    Vendor References

    CVEs related to QID 375421

    Software Advisories
    Advisory ID Software Component Link
    HT212223 URL Logo support.apple.com/en-us/HT212223