CVE-2021-1774 is a critical arbitrary code execution vulnerability affecting multiple Apple operating systems, including macOS, iOS, iPadOS, tvOS, and watchOS. The vulnerability, stemming from insufficient checks, allows an attacker to execute arbitrary code by tricking a user into processing a maliciously crafted image. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, users are strongly advised to update to macOS Big Sur 11.2, Security Update 2021-001 Catalina/Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4, and iPadOS 14.4 to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.4CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 14.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.14, < 10.14.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
>= 10.15, < 10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.14.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.