QID 610378

Date Published: 2021-11-01

QID 610378: Apple iOS 15.1 and iPadOS 15.1 Security Update Missing (HT212867)

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
An integer overflow was addressed through improved input validation. CVE-2021-30907
A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with improved input validation. CVE-2021-30917
This issue was addressed with improved checks. CVE-2021-30903
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30905
An out-of-bounds write was addressed with improved input validation. Available for
An input validation issue was addressed with improved memory handling. CVE-2021-30881
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2021-30914
This issue was addressed with improved checks. CVE-2021-30906
A memory corruption issue was addressed with improved input validation. CVE-2021-30894
A use after free issue was addressed with improved memory management. CVE-2021-30909
A memory corruption issue was addressed with improved memory handling. CVE-2021-30916
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30910
An out-of-bounds read was addressed with improved bounds checking. CVE-2021-30911
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. CVE-2021-30875
A logic issue was addressed with improved state management. CVE-2021-30915
A use after free issue was addressed with improved memory management. CVE-2021-30902
A logic issue was addressed with improved restrictions. CVE-2021-30889
A logic issue was addressed with improved state management. CVE-2021-30890

Affected Devices
iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Refer to Apple advisory HT212867 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212867 iOS URL Logo support.apple.com/en-in/HT212867