MEDIUM

CVE-2021-30657

Apple Mac Os X 2021-09-08 CVSS v3.1
CVSS
5.5
KEV

Description

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

Summary dbcve.org

This is a Gatekeeper bypass vulnerability in macOS where a logic issue in state management allows a malicious application to circumvent Gatekeeper security checks. The vulnerability was being actively exploited in the wild as a zero-day. It affects macOS Catalina and Big Sur prior to the security updates.

Mitigation

Apply macOS Security Update 2021-002 for Catalina or update to macOS Big Sur 11.3 or later to patch the Gatekeeper bypass.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

68.53%
Probability of exploitation in next 30 days
99.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE