Junglewise Threat Intelligence

CVE-2021-1789: Apple Multiple Products Type Confusion Vulnerability

CVE-2021-1789 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-04

Technologies: Apple Safari, Apple iPadOS, Apple watchOS, Apple Multiple Products, Apple Tvos. Vendors: Apple.

Executive brief

A type confusion vulnerability in multiple Apple operating systems and Safari allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed through improved state handling.

Affected products

  • Apple macOS Big Sur Before 11.2
  • Apple macOS Catalina Before Security Update 2021-001
  • Apple macOS Mojave Before Security Update 2021-001
  • Apple tvOS Before 14.4
  • Apple watchOS Before 7.3
  • Apple iOS Before 14.4
  • Apple iPadOS Before 14.4
  • Apple Safari Before 14.0.3

Timeline

  • 2022-05-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-04: disclosed
  • 2021-01-26: patched: Initial vendor security updates released for iOS, iPadOS, and tvOS.

Related threats