QID 610334

Date Published: 2021-05-05

QID 610334: Apple iOS 14.5 and iPadOS 14.5 Security Update Missing (HT212317)

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
This issue was addressed with improved checks. CVE-2021-1835
A certificate validation issue was addressed. CVE-2021-1837
An out-of-bounds read was addressed with improved input validation. CVE-2021-1867
An issue in code signature validation was addressed with improved checks. CVE-2021-1849
A logic issue was addressed with improved restrictions. CVE-2021-1836
A memory corruption issue was addressed with improved validation. CVE-2021-1808
A memory initialization issue was addressed with improved memory handling. CVE-2021-1857
An out-of-bounds read was addressed with improved input validation. CVE-2021-1846
A memory corruption issue was addressed with improved validation. CVE-2021-1809
A validation issue was addressed with improved logic. CVE-2021-30659
A logic issue was addressed with improved state management. CVE-2021-1811
A logic issue was addressed with improved state management. CVE-2021-1872
An out-of-bounds read was addressed with improved input validation. CVE-2021-1881
A memory corruption issue was addressed with improved validation. CVE-2021-1882
A validation issue was addressed with improved logic. CVE-2021-1813
An access issue was addressed with improved memory management. CVE-2021-30656
This issue was addressed with improved checks. CVE-2021-1883
A race condition was addressed with improved locking. CVE-2021-1884
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-1885
This issue was addressed with improved checks. CVE-2021-30653
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2021-1858
A use after free issue was addressed with improved memory management. CVE-2021-1864
An out-of-bounds read was addressed with improved input validation. CVE-2021-1877
A logic issue was addressed with improved state management. CVE-2021-1874
A memory initialization issue was addressed with improved memory handling. CVE-2021-1860
A buffer overflow was addressed with improved bounds checking. CVE-2021-1816
The issue was addressed with improved permissions logic. CVE-2021-1832
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30660
A race condition was addressed with additional validation. CVE-2021-30652
A double free issue was addressed with improved memory management. CVE-2021-1875
A logic issue was addressed with improved restrictions. CVE-2021-1822
An issue obscuring passwords in screenshots was addressed with improved logic. CVE-2021-1865
A parsing issue in the handling of directory paths was addressed with improved path validation. CVE-2021-1815
A validation issue was addressed with improved input sanitization. CVE-2021-1807
The issue was addressed with improved permissions logic. CVE-2021-1831
A logic issue was addressed with improved state management. CVE-2021-1868
A call termination issue with was addressed with improved logic. CVE-2021-1854
The issue was addressed with improved UI handling. CVE-2021-1848
An input validation issue was addressed with improved input validation. CVE-2021-1825
A memory corruption issue was addressed with improved state management. CVE-2021-1817
A logic issue was addressed with improved restrictions. CVE-2021-1826
A memory initialization issue was addressed with improved memory handling. CVE-2021-1820
A use after free issue was addressed with improved memory management. CVE-2021-30661
A use after free issue was addressed with improved memory management. CVE-2020-7463

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Refer to Apple advisory HT212317 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212317 iOS URL Logo support.apple.com/en-in/HT212317