CVE Vulnerabilities

CVE-2021-1765

Published: Apr 02, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Maliciously crafted web content may violate iframe sandboxing policy.

Affected Software

NameVendorStart VersionEnd Version
Mac_os_xApple10.14 (including)10.14.6 (excluding)
Mac_os_xApple10.15 (including)10.15.7 (excluding)
Mac_os_xApple10.14.6 (including)10.14.6 (including)
Mac_os_xApple10.14.6-security_update_2019-004 (including)10.14.6-security_update_2019-004 (including)
Mac_os_xApple10.14.6-security_update_2019-005 (including)10.14.6-security_update_2019-005 (including)
Mac_os_xApple10.14.6-security_update_2019-006 (including)10.14.6-security_update_2019-006 (including)
Mac_os_xApple10.14.6-security_update_2019-007 (including)10.14.6-security_update_2019-007 (including)
Mac_os_xApple10.14.6-security_update_2020-001 (including)10.14.6-security_update_2020-001 (including)
Mac_os_xApple10.14.6-security_update_2020-002 (including)10.14.6-security_update_2020-002 (including)
Mac_os_xApple10.14.6-security_update_2020-003 (including)10.14.6-security_update_2020-003 (including)
Mac_os_xApple10.14.6-security_update_2020-004 (including)10.14.6-security_update_2020-004 (including)
Mac_os_xApple10.14.6-security_update_2020-005 (including)10.14.6-security_update_2020-005 (including)
Mac_os_xApple10.14.6-security_update_2020-006 (including)10.14.6-security_update_2020-006 (including)
Mac_os_xApple10.14.6-security_update_2020-007 (including)10.14.6-security_update_2020-007 (including)
Mac_os_xApple10.14.6-supplemental_update (including)10.14.6-supplemental_update (including)
Mac_os_xApple10.14.6-supplemental_update_2 (including)10.14.6-supplemental_update_2 (including)
Mac_os_xApple10.15.7 (including)10.15.7 (including)
Mac_os_xApple10.15.7-supplemental_update (including)10.15.7-supplemental_update (including)
MacosApple11.0 (including)11.2 (excluding)
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatwebkitgtk4-0:2.48.3-2.el7_9*
Red Hat Enterprise Linux 8RedHatwebkit2gtk3-0:2.32.3-2.el8*
Qtwebkit-opensource-srcUbuntubionic*
Qtwebkit-opensource-srcUbuntudevel*
Qtwebkit-opensource-srcUbuntuesm-apps/bionic*
Qtwebkit-opensource-srcUbuntuesm-apps/focal*
Qtwebkit-opensource-srcUbuntuesm-apps/jammy*
Qtwebkit-opensource-srcUbuntuesm-apps/noble*
Qtwebkit-opensource-srcUbuntuesm-infra/xenial*
Qtwebkit-opensource-srcUbuntufocal*
Qtwebkit-opensource-srcUbuntugroovy*
Qtwebkit-opensource-srcUbuntuhirsute*
Qtwebkit-opensource-srcUbuntuimpish*
Qtwebkit-opensource-srcUbuntujammy*
Qtwebkit-opensource-srcUbuntukinetic*
Qtwebkit-opensource-srcUbuntulunar*
Qtwebkit-opensource-srcUbuntumantic*
Qtwebkit-opensource-srcUbuntunoble*
Qtwebkit-opensource-srcUbuntutrusty*
Qtwebkit-opensource-srcUbuntuupstream*
Qtwebkit-opensource-srcUbuntuxenial*
Qtwebkit-sourceUbuntubionic*
Qtwebkit-sourceUbuntuesm-apps/bionic*
Qtwebkit-sourceUbuntuesm-apps/xenial*
Qtwebkit-sourceUbuntutrusty*
Qtwebkit-sourceUbuntuxenial*
Webkit2gtkUbuntubionic*
Webkit2gtkUbuntudevel*
Webkit2gtkUbuntuesm-infra/bionic*
Webkit2gtkUbuntuesm-infra/focal*
Webkit2gtkUbuntuesm-infra/xenial*
Webkit2gtkUbuntufocal*
Webkit2gtkUbuntugroovy*
Webkit2gtkUbuntuhirsute*
Webkit2gtkUbuntuimpish*
Webkit2gtkUbuntujammy*
Webkit2gtkUbuntukinetic*
Webkit2gtkUbuntulunar*
Webkit2gtkUbuntumantic*
Webkit2gtkUbuntunoble*
Webkit2gtkUbuntuupstream*
Webkit2gtkUbuntuxenial*
WebkitgtkUbuntubionic*
WebkitgtkUbuntuesm-apps/bionic*
WebkitgtkUbuntuesm-apps/xenial*
WebkitgtkUbuntutrusty*
WebkitgtkUbuntuxenial*
WpewebkitUbuntuesm-apps/focal*
WpewebkitUbuntuesm-apps/jammy*
WpewebkitUbuntufocal*
WpewebkitUbuntugroovy*
WpewebkitUbuntuhirsute*
WpewebkitUbuntuimpish*
WpewebkitUbuntujammy*
WpewebkitUbuntutrusty*
WpewebkitUbuntuupstream*

References