Junglewise Threat Intelligence

CVE-2021-1782: Apple Multiple Products Race Condition Vulnerability

CVE-2021-1782 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2021-11-03

Technologies: Apple watchOS, Apple Tvos, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

A race condition in Apple operating systems was addressed with improved locking. A malicious application may exploit this vulnerability to elevate privileges. Apple has acknowledged reports that this issue may have been actively exploited in the wild.

Affected products

  • Apple iOS before 14.4
  • Apple iPadOS before 14.4
  • Apple macOS Big Sur before 11.2
  • Apple macOS Catalina before Security Update 2021-001
  • Apple macOS Mojave before Security Update 2021-001
  • Apple watchOS before 7.3
  • Apple tvOS before 14.4

Timeline

  • 2021-01-26: patched: Apple released updates for iOS, iPadOS, macOS, watchOS, and tvOS.
  • 2021-04-02: disclosed: NVD Published Date.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited: CISA confirmed active exploitation.

Related threats