
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN185
_____________________________________________________________________

DATE                : 29/03/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  iOS, iPadOS versions prior to 14.4.2.

=====================================================================
https://support.apple.com/en-us/HT212256
_____________________________________________________________________


About the security content of iOS 14.4.2 and iPadOS 14.4.2

This document describes the security content of iOS 14.4.2 and iPadOS
14.4.2.


About Apple security updates

For our customers' protection, Apple doesn't disclose, discuss, or
confirm security issues until an investigation has occurred and patches
or releases are available. Recent releases are listed on the Apple
security updates page.

Apple security documents reference vulnerabilities by CVE-ID when
possible.

For more information about security, see the Apple Product Security
page.


iOS 14.4.2 and iPadOS 14.4.2

Released March 26, 2021

WebKit

Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2
and later, iPad 5th generation and later, iPad mini 4 and later, and
iPod touch (7th generation)

Impact: Processing maliciously crafted web content may lead to universal
cross site scripting. Apple is aware of a report that this issue may
have been actively exploited.

Description: This issue was addressed by improved management of object
lifetimes.


CVE-2021-1879: Clement Lecigne of Google Threat Analysis Group and Billy
Leonard of Google Threat Analysis Group

Information about products not manufactured by Apple, or independent
websites not controlled or tested by Apple, is provided without
recommendation or endorsement. Apple assumes no responsibility with
regard to the selection, performance, or use of third-party websites or
products. Apple makes no representations regarding third-party website
accuracy or reliability. Contact the vendor for additional information.


Published Date: March 26, 2021

=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================



