Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 10 min 103 bronnen 1 kritiek 44 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2021-30952

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-190

Beschrijving NL

Apple tvOS, macOS, Safari, iPadOS en watchOS bevatten een integer overflow of wraparound kwetsbaarheid als gevolg van de verwerking van kwaadwillig vervaardigde webinhoud die kan leiden tot het uitvoeren van willekeurige code.

Vereiste actie: pas mitigaties toe volgens de instructies van de leverancier, volg de toepasselijke BOD 22-01-richtlijnen voor cloudservices of stop het gebruik van het product als er geen mitigaties beschikbaar zijn.

Origineel (Engels) tonen

Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Vendors

Apple

Affected products

Multiple Products

References