High severity8.8NVD Advisory· Published Apr 2, 2021· Updated Jun 17, 2026
CVE-2021-1748
CVE-2021-1748
Description
A validation issue was addressed with improved input sanitization. This issue is fixed in tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <14.4
- (no CPE)range: =14.4
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <14.4
- (no CPE)range: =14.4
- (no CPE)range: unspecified
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*range: <7.3
- (no CPE)range: =7.3
- (no CPE)range: unspecified
- Range: =14.4
- Range: unspecified
Patches
Vulnerability mechanics
References
3- support.apple.com/en-us/HT212146nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT212148nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT212149nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.