Junglewise Threat Intelligence

CVE-2021-30883: Apple Multiple Products Memory Corruption Vulnerability

CVE-2021-30883 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-23

Technologies: Apple macOS Monterey, Apple watchOS, Apple iPadOS, Apple Multiple Products, Apple Tvos. Vendors: Apple.

Executive brief

A memory corruption vulnerability in multiple Apple operating systems allows an application to execute arbitrary code with kernel privileges. The issue stems from improper memory handling and has been reported as being actively exploited in the wild.

Affected products

  • Apple iOS < 14.8.1, 15.0 - 15.0.1
  • Apple iPadOS < 14.8.1, 15.0 - 15.0.1
  • Apple macOS Monterey < 12.0.1
  • Apple macOS Big Sur 11.0 - 11.6.1
  • Apple tvOS < 15.1
  • Apple watchOS < 8.1

Timeline

  • 2021-10-11: patched: Fixed in iOS 15.0.2 and iPadOS 15.0.2
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-23: disclosed: NVD publication date

Related threats