QID 375991

Date Published: 2021-10-27

QID 375991: Apple macOS Security Update 2021-007 Catalina (HT212871)

Apple has released this Security Update for multiple vulnerabilities

Affected versions:
Prior to Apple macOS Security Update 2021-007 Catalina.

QID Detection Logic (Authenticated):
This QID looks for the missing security patches from Catalina

Here are the list of consequences:

AppleScript: Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Audio: A malicious application may be able to elevate privileges.
Bluetooth: A malicious application may be able to execute arbitrary code with kernel privileges.
ColorSync: Processing a maliciously crafted image may lead to arbitrary code execution.
CoreAudio: Processing a malicious audio file may result in unexpected application termination or arbitrary code execution.
CoreAudio: Processing a maliciously crafted file may disclose user information.
CoreGraphics: Processing a maliciously crafted PDF may lead to arbitrary code execution.
FileProvider: Unpacking a maliciously crafted archive may lead to arbitrary code execution.
Intel Graphics Driver: A malicious application may be able to execute arbitrary code with kernel privileges.
IOGraphics: A malicious application may be able to execute arbitrary code with kernel privileges.
Kernel: An application may be able to execute arbitrary code with kernel privileges.
Model I/O: Processing a maliciously crafted file may disclose user information.
SoftwareUpdate: A malicious application may gain access to a user's Keychain items.
UIKit: A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
zsh: A malicious application may be able to modify protected parts of the file system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    The vendor has released these fixes: Security Update 2021-007 Catalina.

    More information regarding the update can be found at HT212871.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212871 URL Logo support.apple.com/en-us/HT212871
    © CVE.report 2026 |

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report