Apple fixes CVE-2021-1844 RCE that affects iOS, macOS, watchOS, and Safari
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1782 | Race Condition Privilege Escalation in Apple iOS, macOS, watchOS, and tvOS A race condition caused by improper locking (CWE-667) in Apple's operating systems could allow local privilege escalation. The flaw is triggered by a malicious application already running on the device that exploits a timing race; exploitation requires only low local privileges and no user interaction, though the attack complexity is rated high. A successful attacker gains elevated privileges with high impact to the confidentiality, integrity, and availability of the device. Users of iPhone, iPad, Mac, Apple Watch, and Apple TV running versions earlier than iOS/iPadOS 14.4, macOS Big Sur 11.2 (or the 2021-001 security updates for Catalina and Mojave), watchOS 7.3, and tvOS 14.4 are affected. Apple reported the issue as actively exploited in the wild, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and no public proof-of-concept is known. Do: Upgrade to iOS/iPadOS 14.4, watchOS 7.3, and tvOS 14.4; on Macs, upgrade to macOS Big Sur 11.2 or apply Security Update 2021-001 for Catalina and Mojave. As an interim mitigation, avoid installing untrusted applications, since exploitation requires a malicious local app. This vulnerability is in the CISA KEV catalog, so organizations subject to the required action should verify that all managed Apple devices are running the patched versions. | 7.0 | 2% | KEV |
| masshundreds of millions of Apple devices (estimate based on Apple's active installed base exceeding 1 billion devices) | |
| CVE-2021-1844 | A memory corruption issue was addressed with improved validation. A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing maliciously crafted web content may lead to arbitrary code execution. NVD description · AI analysis pending | 8.8 | 2% |
| — |
Full article297 words · extracted from securityaffairs.com · click to collapse

Apple released out-of-band patches to address a remote code execution, tracked as CVE-2021-1844, that affect iOS, macOS, watchOS, and Safari web browser.
Apple has released out-of-band security patches to address a critical iOS, macOS, watchOS, and Safari web browser to address a security flaw tracked as CVE-2021-1844.
The vulnerability was discovered by Clément Lecigne of Google’s Threat Analysis Group and Alison Huffman of Microsoft Browser Vulnerability Research. The flaw could be exploited by remote attackers to run arbitrary code on vulnerable devices by tricking users into visiting a malicious web content.
The vulnerability is caused by a memory corruption issue that could be triggered to cause arbitrary code execution when processing specially crafted web content.
“Processing maliciously crafted web content may lead to arbitrary code execution.” reads the advisory published by Apple. “Description: A memory corruption issue was addressed with improved validation.”
Apple has improved validation to address the vulnerability.
Apple has released an update for devices running iOS 14.4, iPadOS 14.4, macOS Big Sur, and watchOS 7.3.1 (Apple Watch Series 3 and later). Apple also released an update to Safari for MacBooks running macOS Catalina and macOS Mojave.
In March, Pwn20wnd, the author of the jailbreaking tool “unc0ver,” has updated their software to support iOS 14.3 and earlier releases. The last release of the jailbreaking tool, unc0ver v6.0.0, now includes the exploit code for the CVE-2021-1782 vulnerability that Apple in January claimed was actively exploited by threat actors. The CVE-2021-1782 flaw is a race condition issue that resides in the iOS operating system kernel.
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, CVE-2021-1844)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/115423/hacking/apple-cve-2021-1844-rce.html