CISA Known Exploited Vulnerability

CVE-2021-30860

Apple · Multiple Products

Apple Multiple Products Integer Overflow Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20, CWE-190
Ransomware Unknown

CISA description

Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.

Required action

Apply updates per vendor instructions.