HIGH
CVE-2021-30807
CVSS
7.8
KEV
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Summary dbcve.org
Memory corruption vulnerability in Apple kernel (XNU) that allows a malicious application to escalate privileges to kernel level and execute arbitrary code. The issue was addressed with improved memory handling in the patched versions.
Mitigation
Apply security updates immediately: macOS Big Sur 11.5.1, iOS/iPadOS 14.7.1, or watchOS 7.6.1 to all affected devices. Given active exploitation in the wild, prioritize patching.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
28.84%
Probability of exploitation in next 30 days
98.1th percentile
References
https://support.apple.com/en-us/HT212622
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT212623
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT212713
Release Notes, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30807
Third Party Advisory, US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.