CVE-2021-30663
CVE-2021-30663
In short
A vulnerability in how Apple devices handle large numbers in web content can cause the system to crash or run malicious code. This happens when specially crafted websites exploit how the device calculates with these large numbers.
Technical detail
An integer overflow vulnerability in web content processing allows remote code execution through crafted input that exceeds integer bounds. The attack requires user interaction to view malicious web content, with the overflow leading to memory corruption and arbitrary code execution.
Summary generated and translated by AI from the official description.
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Apple · macOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →