Unknown · CVSS Not scored
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A sandboxed process may be able to circumvent sandbox restrictions.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 15 and iPadOS 15. A 3D model constructed to look like the enrolled user may be able to authenticate via Face ID.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Processing a maliciously crafted AppleScript binary may result in unexpected application termination or disclosure of process memory.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions. This issue is fixed in macOS Big Sur 11.3. A malicious unsandboxed app on a system with Remote Login enabled may bypass Privacy preferences.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to modify protected parts of the file system.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. An application may be able to execute arbitrary code with kernel privileges.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Unpacking a maliciously crafted archive may lead to arbitrary code execution.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6. A malicious application may bypass Gatekeeper checks.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to elevate privileges.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A sync issue was addressed with improved state validation. This issue is fixed in macOS Monterey 12.0.1. A user's messages may continue to sync after the user has signed out of iMessage.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1. An application may be able to execute arbitrary code with kernel privileges.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
This issue was addressed with a new entitlement. This issue is fixed in iOS 14.7, watchOS 7.6, macOS Big Sur 11.5. A local attacker may be able to access analytics data.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A logic issue was addressed with improved state management. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A sandboxed process may be able to circumvent sandbox restrictions.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A race condition was addressed with improved locking. This issue is fixed in macOS Monterey 12.0.1, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina. Processing a maliciously crafted file may disclose user information.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. A VPN configuration may be installed by an app without user permission.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may bypass Gatekeeper checks.
Published Aug 24, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 26, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Stack buffer overflow in Printing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit stack corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024
Unknown · CVSS Not scored
Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Aug 3, 2021 · Updated Aug 3, 2024