PatchSiren

Apple CVE debriefs · Page 13

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30858

CVE-2021-30858 is a use-after-free vulnerability affecting Apple iOS, iPadOS, and macOS. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating it has been observed in active exploitation. Apple users and administrators should treat this as a high-priority remediation item and apply vendor updates as soon as possible.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30807

CVE-2021-30807 is an Apple memory corruption vulnerability affecting multiple products and listed by CISA in the Known Exploited Vulnerabilities catalog. Because CISA added it to KEV on 2021-11-03 with a remediation due date of 2021-11-17, defenders should treat it as a high-priority patching item and follow Apple’s update guidance for affected systems.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30762

CVE-2021-30762 is an Apple iOS WebKit use-after-free vulnerability that CISA placed in the Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is listed in KEV, defenders should treat it as a confirmed exploitation risk and prioritize vendor updates over routine patch queues.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30761

CVE-2021-30761 is an Apple iOS WebKit memory corruption vulnerability that CISA included in its Known Exploited Vulnerabilities (KEV) catalog. For defenders, the key takeaway is not the internal bug detail but the exposure signal: CISA marked it as a known exploited issue and set a remediation due date of 2021-11-17. Follow Apple’s update guidance and prioritize deployment on iOS devices that may still be [truncated]

Known exploited Apple CVE published 2021-11-03

CVE-2021-30713

CVE-2021-30713 is an Apple macOS vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03, with remediation due by 2021-11-17. The supplied corpus does not provide technical details beyond the fact that it is an unspecified macOS vulnerability, but CISA’s inclusion indicates active exploitation concerns and makes this a high-priority patching item for Apple-managed endpoints.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30666

CVE-2021-30666 is an Apple iOS WebKit buffer overflow vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key signal is not just the vulnerability type, but the fact that it was added to the KEV list, which indicates known exploitation and makes timely patching a priority. CISA’s record lists the required action as applying updates per vendor instructions.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30665

CVE-2021-30665 is an Apple WebKit memory corruption vulnerability affecting multiple Apple products. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2021-11-03, which indicates known exploitation risk and makes timely patching a priority for organizations using Apple devices and WebKit-based software.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30663

CVE-2021-30663 is a CISA-listed Known Exploited Vulnerability affecting Apple multiple products and described as a WebKit integer overflow vulnerability. Because CISA added it to the KEV catalog on the CVE publication date and set a remediation due date two weeks later, defenders should treat it as a high-priority patching item and follow Apple’s update guidance.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30661

CVE-2021-30661 is an Apple WebKit Storage use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. That KEV listing means the issue is considered known to be exploited in the wild, so defenders should treat Apple patching as urgent and verify that vendor updates have been applied across managed devices.

Known exploited Apple CVE published 2021-11-03

CVE-2021-30657

CVE-2021-30657 is a macOS issue that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03, which means it was considered actively exploited or otherwise confirmed in the wild at that time. The public records provided here do not describe the underlying flaw in detail, so the safest response is straightforward patching and exposure reduction: follow Apple’s update guidance and confirm al [truncated]

Known exploited Apple CVE published 2021-11-03

CVE-2021-1879

CVE-2021-1879 is a WebKit cross-site scripting (XSS) vulnerability affecting Apple iOS, iPadOS, and watchOS. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and set a due date of 2021-11-17, indicating it should be treated as an actively prioritized remediation item.

Known exploited Apple CVE published 2021-11-03

CVE-2021-1871

CVE-2021-1871 is a CISA Known Exploited Vulnerabilities (KEV) entry for Apple iOS, iPadOS, and macOS. The issue is identified as a WebKit remote code execution vulnerability, which makes it a high-priority patch item for Apple device fleets. CISA added it to KEV on 2021-11-03 and set a remediation due date of 2021-11-17, so organizations should treat it as actively important and verify updates were applie [truncated]

Known exploited Apple CVE published 2021-11-03

CVE-2021-1870

CVE-2021-1870 is an Apple WebKit remote code execution vulnerability affecting iOS, iPadOS, and macOS. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and set a remediation due date of 2021-11-17, so this should be treated as a patch-now issue for exposed Apple fleets.

Known exploited Apple CVE published 2021-11-03

CVE-2021-1782

CVE-2021-1782 is an Apple multiple-products race condition vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is in KEV, defenders should treat it as a priority patching item and follow Apple’s update guidance as soon as possible.

Known exploited Apple CVE published 2021-11-03

CVE-2020-9859

CVE-2020-9859 is an Apple Multiple Products code execution vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. Because it appears in KEV, defenders should treat it as a high-priority issue and apply Apple’s update guidance without delay across relevant environments.

Known exploited Apple CVE published 2021-11-03

CVE-2020-9819

CVE-2020-9819 is an Apple memory corruption vulnerability affecting iOS, iPadOS, and watchOS. The most important operational signal in the supplied sources is that CISA lists it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as a patch priority rather than a routine platform update. Because the supplied corpus does not include deeper technical detail, the safest resp [truncated]

Known exploited Apple CVE published 2021-11-03

CVE-2020-9818

CVE-2020-9818 is an Apple out-of-bounds write issue affecting iOS, iPadOS, and watchOS. CISA has placed it in the Known Exploited Vulnerabilities catalog, so defenders should treat remediation as urgent and follow vendor update guidance.

Known exploited Apple CVE published 2021-11-03

CVE-2020-27950

CVE-2020-27950 is an Apple multiple-products memory initialization vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because it is flagged as known exploited, organizations should treat it as a high-priority patching item and follow vendor update guidance without delay.

Known exploited Apple CVE published 2021-11-03

CVE-2020-27932

CVE-2020-27932 is described as a type confusion vulnerability affecting multiple Apple products. CISA added it to the Known Exploited Vulnerabilities catalog, which indicates known exploitation and makes remediation a high priority for any environment running Apple devices. The supplied corpus does not provide impacted-version detail or deeper technical context, so defenders should use the official CVE, N [truncated]

Known exploited Apple CVE published 2021-11-03

CVE-2020-27930

CVE-2020-27930 is an Apple memory corruption vulnerability affecting multiple products and was added to CISA’s Known Exploited Vulnerabilities catalog. That designation means CISA had evidence of active exploitation, so defenders should treat it as a high-priority patching and exposure-management item. The supplied corpus does not include detailed affected-component or exploit-behavior information, so res [truncated]

Known exploited Apple CVE published 2021-11-03

CVE-2019-6223

CVE-2019-6223 is an Apple iOS and macOS Group FaceTime vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog. Because it is in KEV, defenders should treat it as a real-world risk and prioritize vendor-recommended patching or mitigation on affected Apple devices.

HIGH Apple CVE published 2017-02-20

CVE-2017-2374

CVE-2017-2374 is a memory corruption flaw in the Projects component of Apple GarageBand versions before 10.1.6. According to the NVD record, a crafted GarageBand project file can trigger application crash or arbitrary code execution, so updating to a fixed release is the primary mitigation.

HIGH Apple CVE published 2017-02-20

CVE-2017-2373

CVE-2017-2373 is a high-severity WebKit memory corruption vulnerability affecting Apple platforms and browser components. According to the CVE record, a crafted website could trigger remote code execution or a denial of service through application crash. The affected Apple versions listed in the record are iOS before 10.2.1, Safari before 10.0.3, and tvOS before 10.1.1. The NVD record also lists WebKitGTK [truncated]

HIGH Apple CVE published 2017-02-20

CVE-2017-2372

CVE-2017-2372 is a High-severity Apple memory corruption issue affecting GarageBand and Logic Pro X when processing crafted GarageBand project files. The record says a remote attacker could trigger arbitrary code execution or denial of service, and the CVSS vector requires user interaction to open the malicious file.

MEDIUM Apple CVE published 2017-02-20

CVE-2017-2371

CVE-2017-2371 describes a WebKit issue in Apple iOS before 10.2.1 that let a remote attacker use a crafted website to launch popups. NVD assigns the issue a medium severity score and identifies user interaction as part of the attack path.

HIGH Apple CVE published 2017-02-20

CVE-2017-2370

CVE-2017-2370 is an Apple Kernel buffer overflow issue that can let a crafted app trigger arbitrary code execution in a privileged context or cause a denial of service. The public record says it affects iOS before 10.2.1, macOS before 10.12.3, tvOS before 10.1.1, and watchOS before 3.1.3. The NVD record classifies the weakness as CWE-119 and gives it a CVSS 3.0 score of 7.8 (HIGH).

HIGH Apple CVE published 2017-02-20

CVE-2017-2369

CVE-2017-2369 is a high-severity WebKit memory-corruption issue publicly disclosed on 2017-02-20. According to the CVE description and NVD metadata, a crafted website could let a remote attacker trigger application crash or arbitrary code execution on affected Apple products, with NVD also listing WebKitGTK+ as vulnerable. Because the attack is network-reachable and requires only user interaction with mal [truncated]

MEDIUM Apple CVE published 2017-02-20

CVE-2017-2368

CVE-2017-2368 is a medium-severity Apple iOS vulnerability in the Contacts component. According to the NVD record, iOS versions before 10.2.1 were affected and a crafted contact card could cause the Contacts app to crash, resulting in denial of service. The published CVSS vector indicates user interaction is required and the impact is availability-only.

HIGH Apple CVE published 2017-02-20

CVE-2017-2366

CVE-2017-2366 is a high-severity Apple WebKit memory-corruption issue that can be triggered by a crafted website. The CVE description says it may allow remote code execution or cause a denial of service through application crash, affecting iOS, Safari, iCloud, and iTunes versions released before the fixed updates named in the record.

MEDIUM Apple CVE published 2017-02-20

CVE-2017-2365

CVE-2017-2365 is a medium-severity WebKit information-disclosure issue affecting Apple platforms and related WebKit builds. A remote attacker can use a crafted website to bypass the Same Origin Policy and read sensitive information. The NVD record maps the issue to iOS before 10.2.1, Safari before 10.0.3, tvOS before 10.1.1, and WebKitGTK+ before 2.16.3.