Executive brief
A type confusion vulnerability in multiple Apple operating systems and Safari allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed through improved state handling.
Affected products
- Apple macOS Big Sur Before 11.2
- Apple macOS Catalina Before Security Update 2021-001
- Apple macOS Mojave Before Security Update 2021-001
- Apple tvOS Before 14.4
- Apple watchOS Before 7.3
- Apple iOS Before 14.4
- Apple iPadOS Before 14.4
- Apple Safari Before 14.0.3
Timeline
- 2022-05-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-04: disclosed
- 2021-01-26: patched: Initial vendor security updates released for iOS, iPadOS, and tvOS.