Security News > 2021 > June > Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild

Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild
2021-06-15 03:08

Apple on Monday shipped out-of-band security patches to address two zero-day vulnerabilities in iOS 12.5.3 that it says are being actively exploited in the wild.

The latest update, iOS 12.5.4, comes with fixes for three security bugs, including a memory corruption issue in ASN.1 decoder and two flaws concerning its WebKit browser engine that could be abused to achieve remote code execution -.

CVE-2021-30761 - A memory corruption issue that could be exploited to gain arbitrary code execution when processing maliciously crafted web content.

CVE-2021-30762 - A use-after-free issue that could be exploited to gain arbitrary code execution when processing maliciously crafted web content.

CVE-2021-30665 - Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2021-30666 - Processing maliciously crafted web content may lead to arbitrary code execution.


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/eKzhIwJnEks/apple-issues-urgent-patches-for-2-zero.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-09-08 CVE-2021-30666 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS
A buffer overflow issue was addressed with improved memory handling.
network
low complexity
apple CWE-119
8.8
2021-09-08 CVE-2021-30665 Out-of-bounds Write vulnerability in Apple products
A memory corruption issue was addressed with improved state management.
network
low complexity
apple CWE-787
8.8
2021-09-08 CVE-2021-30762 Use After Free vulnerability in Apple Iphone OS
A use after free issue was addressed with improved memory management.
network
low complexity
apple CWE-416
8.8
2021-09-08 CVE-2021-30761 Out-of-bounds Write vulnerability in Apple Iphone OS
A memory corruption issue was addressed with improved state management.
network
low complexity
apple CWE-787
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apple 68 212 1433 2208 257 4110