QID 610370

Date Published: 2021-09-28

QID 610370: Apple iOS 15 and iPadOS 15 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A memory consumption issue was addressed with improved memory handling. CVE-2021-30837
This issue was addressed with improved checks. CVE-2021-30811
A memory corruption issue was addressed with improved memory handling. CVE-2021-30838
This issue was addressed with improved checks. CVE-2021-30825
This issue was addressed by improving Face ID anti-spoofing models. CVE-2021-30863
This issue was addressed with improved checks. CVE-2021-30841
This issue was addressed with improved checks. CVE-2021-30835
A race condition was addressed with improved locking. CVE-2021-30857
This issue was addressed by updating expat to version 2.4.1. CVE-2013-0340
An out-of-bounds read was addressed with improved input validation. CVE-2021-30819
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. CVE-2021-30855
A logic issue was addressed with improved state management. CVE-2021-30854
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. CVE-2021-30815
A logic issue was addressed with improved state management. CVE-2021-30826
A memory corruption issue was addressed with improved memory handling. CVE-2021-30846
A memory corruption issue was addressed with improved memory handling. CVE-2021-30848
Multiple memory corruption issues were addressed with improved memory handling. CVE-2021-30849
A memory corruption vulnerability was addressed with improved locking. CVE-2021-30851
An authorization issue was addressed with improved state management. CVE-2021-30810

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Apple advisory HT212814 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212814 iOS URL Logo support.apple.com/en-in/HT212814