Executive brief
A type confusion vulnerability in the XNU kernel of Apple iOS, iPadOS, and macOS allows a malicious application to execute arbitrary code with kernel privileges. The issue stems from improper state handling and has been observed being exploited in the wild.
Affected products
- Apple iOS < 12.5.5, 14.0 to < 14.4
- Apple iPadOS < 14.4
- Apple macOS Big Sur < 11.2
- Apple macOS Catalina 10.15.7 (prior to Security Update 2021-006)
- Apple macOS Mojave 10.14.6 (prior to Security Update 2021-001)
Timeline
- 2021-09-23: patched: Apple released updates for iOS 12.5.5 and macOS Catalina.
- 2021-11-03: disclosed: Vulnerability published and added to CISA KEV.
- 2021-11-03: kev added
- 2021-11-03: exploited: Apple reported awareness of active exploitation in the wild.