CVE-2021-30952

An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References
Link Resource
http://www.openwall.com/lists/oss-security/2022/01/21/2 Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7EQVZ3CEMTINLBZ7PBC7WRXVEVCRHNSM/ Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQKWD4BXRDD2YGR5AVU7H5J5PIQIEU6V/ Broken Link
https://support.apple.com/en-us/HT212975 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212976 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212978 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212980 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212982 Release Notes Vendor Advisory
https://www.debian.org/security/2022/dsa-5060 Mailing List Third Party Advisory
https://www.debian.org/security/2022/dsa-5061 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/01/21/2 Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7EQVZ3CEMTINLBZ7PBC7WRXVEVCRHNSM/ Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQKWD4BXRDD2YGR5AVU7H5J5PIQIEU6V/ Broken Link
https://support.apple.com/en-us/HT212975 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212976 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212978 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212980 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT212982 Release Notes Vendor Advisory
https://www.debian.org/security/2022/dsa-5060 Mailing List Third Party Advisory
https://www.debian.org/security/2022/dsa-5061 Mailing List Third Party Advisory
https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit Exploit Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30952 US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-08-24 19:15

Updated : 2026-03-06 13:44


NVD link : CVE-2021-30952

Mitre link : CVE-2021-30952

CVE.ORG link : CVE-2021-30952


JSON object : View

Products Affected

apple

  • watchos
  • macos
  • ipados
  • safari
  • iphone_os
  • tvos

debian

  • debian_linux

fedoraproject

  • fedora

wpewebkit

  • wpe_webkit

webkitgtk

  • webkitgtk
CWE
CWE-190

Integer Overflow or Wraparound