Junglewise Threat Intelligence

CVE-2021-30869: Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

CVE-2021-30869 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple macOS, Apple iPadOS. Vendors: Apple.

Executive brief

A type confusion vulnerability in the XNU kernel of Apple iOS, iPadOS, and macOS allows a malicious application to execute arbitrary code with kernel privileges. The issue stems from improper state handling and has been observed being exploited in the wild.

Affected products

  • Apple iOS < 12.5.5, 14.0 to < 14.4
  • Apple iPadOS < 14.4
  • Apple macOS Big Sur < 11.2
  • Apple macOS Catalina 10.15.7 (prior to Security Update 2021-006)
  • Apple macOS Mojave 10.14.6 (prior to Security Update 2021-001)

Timeline

  • 2021-09-23: patched: Apple released updates for iOS 12.5.5 and macOS Catalina.
  • 2021-11-03: disclosed: Vulnerability published and added to CISA KEV.
  • 2021-11-03: kev added
  • 2021-11-03: exploited: Apple reported awareness of active exploitation in the wild.

Related threats