Junglewise Threat Intelligence

CVE-2021-30983: Apple iOS and iPadOS Buffer Overflow Vulnerability

CVE-2021-30983 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-06-27

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

A buffer overflow vulnerability in Apple iOS and iPadOS was addressed through improved memory handling. A local application may exploit this flaw to execute arbitrary code with kernel privileges.

Affected products

  • Apple iOS < 15.2
  • Apple iPadOS < 15.2

Timeline

  • 2021-08-24: disclosed: NVD Published Date
  • 2021-12-23: patched: Fixed in iOS 15.2 and iPadOS 15.2
  • 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-27: exploited: Reported as exploited in the wild

Related threats