Executive brief
A memory corruption vulnerability in the IOMobileFrameBuffer component of multiple Apple operating systems allows an application to execute arbitrary code with kernel privileges. The issue stems from improper memory handling and has been reported as being actively exploited in the wild.
Affected products
- Apple iOS < 14.7.1
- Apple iPadOS < 14.7.1
- Apple macOS Big Sur < 11.5.1
- Apple watchOS < 7.6.1
Timeline
- 2021-10-19: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-07-26: patched: Fixed in macOS Big Sur 11.5.1, iOS 14.7.1, iPadOS 14.7.1, and watchOS 7.6.1
- 2021-10-19: exploited: Apple aware of reports of active exploitation at time of disclosure