Junglewise Threat Intelligence

CVE-2021-30900: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

CVE-2021-30900 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-03-30

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

An out-of-bounds write vulnerability in Apple GPU drivers allows a malicious application to execute arbitrary code with kernel privileges. The issue was addressed through improved bounds checking in iOS, iPadOS, and macOS.

Affected products

  • Apple iOS up to (excluding) 14.8.1, 15.0
  • Apple iPadOS up to (excluding) 14.8.1, 15.0
  • Apple macOS Big Sur up to (excluding) 11.6.1

Timeline

  • 2021-10-26: patched: Fixed in iOS 14.8.1, iPadOS 14.8.1, and macOS Big Sur 11.6.1
  • 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-30: disclosed: NVD publication date

Related threats