Junglewise Threat Intelligence

CVE-2021-30713: Apple macOS Unspecified Vulnerability

CVE-2021-30713 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple macOS. Vendors: Apple.

Executive brief

Apple macOS Transparency, Consent, and Control (TCC) contains a permissions validation issue that allows a malicious application to bypass privacy preferences. This vulnerability enables unauthorized access to user data by circumventing established security prompts and permissions.

Affected products

  • Apple macOS Big Sur up to (excluding) 11.4
  • Apple macOS Catalina 10.15.7 and earlier

Timeline

  • 2021-05-24: patched: Fixed in macOS Big Sur 11.4
  • 2021-09-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Apple is aware of reports that this issue may have been actively exploited.

Related threats