QID 610367

Date Published: 2021-09-14

QID 610367: Apple iOS 14.8 and iPadOS 14.8 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
An integer overflow was addressed with improved input validation. CVE-2021-30860
A use after free issue was addressed with improved memory management. CVE-2021-30858

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT212807 for patching details.
    Vendor References

    CVEs related to QID 610367

    Software Advisories
    Advisory ID Software Component Link
    HT212807 iOS URL Logo support.apple.com/en-in/HT212807