HIGH

CVE-2021-30713

Apple Mac Os X 2021-09-08 CVSS v3.1
CVSS
7.8
KEV

Description

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..

Summary dbcve.org

This is a permissions bypass vulnerability in macOS Big Sur affecting the system's Privacy controls (likely TCC - Transparency, Consent, and Control). A malicious application could exploit improper validation to bypass user privacy preferences, potentially accessing sensitive user data or system resources without authorization. The vulnerability was being actively exploited in the wild at the time of the fix.

Mitigation

Upgrade to macOS Big Sur 11.4 or later to apply the patch. In enterprise environments, deploy the OS update through patch management infrastructure and verify privacy controls remain intact.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

7.04%
Probability of exploitation in next 30 days
94th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE