CVE-2021-30959
Description
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in macOS audio parsing lets a crafted file disclose user information; fixed in macOS Big Sur 11.6.2 and Security Update 2021-008 Catalina.
Vulnerability
A buffer overflow issue exists in the audio file parsing code of macOS, affecting systems prior to macOS Big Sur 11.6.2 and Security Update 2021-008 Catalina. The vulnerability is triggered when processing a maliciously crafted audio file, leading to memory corruption. Affected versions include macOS Big Sur before 11.6.2 and macOS Catalina before the Security Update 2021-008.
Exploitation
An attacker must craft a malicious audio file and deliver it to the target user. The user then needs to open or parse the audio file with an application that invokes the vulnerable audio parsing code (for example, QuickTime Player or any app using the system audio decoder). No additional authentication or elevated privileges are required for the attack vector; it is a standard user-interaction scenario.
Impact
Successful exploitation of the buffer overflow can lead to disclosure of user information. The impact is limited to information disclosure; the description does not indicate arbitrary code execution or privilege escalation. The attacker may gain access to data that was otherwise protected within the system's memory.
Mitigation
Apple released fixes on December 13, 2021: macOS Big Sur 11.6.2 and Security Update 2021-008 Catalina. Users should update to these or later versions to remediate the vulnerability. No workarounds are provided in the available references [1], [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3< 11.6.2+ 1 more
- (no CPE)range: < 11.6.2
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.apple.com/en-us/HT212979mitrex_refsource_MISC
- support.apple.com/en-us/HT212981mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.