Apple Multiple Products Integer Overflow Vulnerability
Apple · Multiple Products
Date added (CISA)
2021-11-03
Remediation due
2021-11-17
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.