6.8
CVSSv2

CVE-2021-1858

Published: 08/09/2021 Updated: 17/09/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

This vulnerability allows remote malicious users to disclose sensitive information on affected installations of Apple macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the DecodeRow function. Crafted data in a KTX image can trigger a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple ipados

apple iphone os

apple mac os x 10.14

apple mac os x 10.14.0

apple mac os x 10.14.1

apple mac os x 10.14.2

apple mac os x 10.14.3

apple mac os x 10.14.4

apple mac os x 10.14.5

apple mac os x 10.14.6

apple mac os x 10.15

apple mac os x 10.15.1

apple mac os x 10.15.2

apple mac os x 10.15.3

apple mac os x 10.15.4

apple mac os x 10.15.5

apple mac os x 10.15.6

apple mac os x 10.15.7

apple macos

apple tvos

apple watchos

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-04-26-2 macOS Big Sur 113 macOS Big Sur 113 addresses the following issues Information about the security content is also available at supportapplecom/HT212325 APFS Available for: macOS Big Sur Impact: A local attacker may be able to elevate their privileges Description: ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-04-26-1 iOS 145 and iPadOS 145 iOS 145 and iPadOS 145 addresses the following issues Information about the security content is also available at supportapplecom/HT212317 Accessibility Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-04-26-5 watchOS 74 watchOS 74 addresses the following issues Information about the security content is also available at supportapplecom/HT212324 AppleMobileFileIntegrity Available for: Apple Watch Series 3 and later Impact: A malicious application may be able to bypass ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-04-26-6 tvOS 145 tvOS 145 addresses the following issues Information about the security content is also available at supportapplecom/HT212323 AppleMobileFileIntegrity Available for: Apple TV 4K and Apple TV HD Impact: A malicious application may be able to bypass Privacy ...