Junglewise Threat Intelligence

CVE-2021-30860: Apple Multiple Products Integer Overflow Vulnerability

CVE-2021-30860 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple iPadOS, Apple watchOS, Apple Multiple Products. Vendors: Apple.

Executive brief

An integer overflow vulnerability in Apple's CoreGraphics framework, known as FORCEDENTRY, allows for arbitrary code execution when processing a maliciously crafted PDF. The flaw was addressed through improved input validation across multiple Apple operating systems.

Affected products

  • Apple iOS before 14.8
  • Apple iPadOS before 14.8
  • Apple macOS Big Sur before 11.6
  • Apple Security Update 2021-005 Catalina before update
  • Apple watchOS before 7.6.2

Timeline

  • 2021-11-03: disclosed: Published in NVD and added to CISA KEV catalog.
  • 2021-11-03: kev added
  • 2021-09-13: patched: Apple released security updates for iOS, iPadOS, macOS, and watchOS.
  • 2021-09-13: exploited: Apple reported awareness of active exploitation at the time of patching.

Related threats