QID 610342

Date Published: 2021-05-27

QID 610342: Apple iOS 14.6 and iPadOS 14.6 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
This issue was addressed with improved checks. CVE-2021-30707
This issue was addressed with improved checks. CVE-2021-30685
A race condition was addressed with improved state handling. CVE-2021-30714
A logic issue was addressed with improved restrictions. CVE-2021-30729
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. CVE-2021-30681
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30686
A logic issue was addressed with improved state management. CVE-2021-30727
This issue was addressed with improved checks. CVE-2021-30724
A logic issue was addressed with improved state management. CVE-2021-30697
A memory corruption issue was addressed with improved state management. CVE-2021-30710
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30687
This issue was addressed with improved checks. CVE-2021-30700
This issue was addressed with improved checks. CVE-2021-30701
This issue was addressed with improved checks. CVE-2021-30705
A logic issue was addressed with improved validation. CVE-2021-30740
This issue was addressed with improved checks. CVE-2021-30674
A logic issue was addressed with improved state management. CVE-2021-30704
A logic issue was addressed with improved state management. CVE-2021-30715
A buffer overflow was addressed with improved size validation. CVE-2021-30736
This issue was addressed with improved environment sanitization. CVE-2021-30677
A use after free issue was addressed with improved memory management. CVE-2021-30741
An information disclosure issue was addressed with improved state management. CVE-2021-30723
A memory corruption issue was addressed with improved state management. CVE-2021-30725
An out-of-bounds read was addressed with improved input validation. CVE-2021-30746
A validation issue was addressed with improved logic. CVE-2021-30693
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30695
An out-of-bounds read was addressed with improved input validation. CVE-2021-30708
This issue was addressed with improved checks. CVE-2021-30709
A window management issue was addressed with improved state management. CVE-2021-30699
A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. CVE-2021-30737
A use after free issue was addressed with improved memory management. CVE-2021-21779
A logic issue was addressed with improved restrictions. CVE-2021-30682
A logic issue was addressed with improved state management. CVE-2021-30689
Multiple memory corruption issues were addressed with improved memory handling. CVE-2021-30749
A logic issue was addressed with improved restrictions. CVE-2021-30720
A null pointer dereference was addressed with improved input validation. CVE-2021-23841
A logic issue was addressed with improved validation. CVE-2021-30667

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Apple advisory HT212528 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212528 iOS URL Logo support.apple.com/en-in/HT212528