Junglewise Threat Intelligence

CVE-2021-30807: Apple Multiple Products Memory Corruption Vulnerability

CVE-2021-30807 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple watchOS, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

A memory corruption vulnerability in the IOMobileFrameBuffer component of multiple Apple operating systems allows an application to execute arbitrary code with kernel privileges. The issue stems from improper memory handling and has been reported as being actively exploited in the wild.

Affected products

  • Apple iOS < 14.7.1
  • Apple iPadOS < 14.7.1
  • Apple macOS Big Sur < 11.5.1
  • Apple watchOS < 7.6.1

Timeline

  • 2021-10-19: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-07-26: patched: Fixed in macOS Big Sur 11.5.1, iOS 14.7.1, iPadOS 14.7.1, and watchOS 7.6.1
  • 2021-10-19: exploited: Apple aware of reports of active exploitation at time of disclosure

Related threats