CVE-2021-1782
KEVmassRace Condition Privilege Escalation in Apple iOS, macOS, watchOS, and tvOS
CISA: Apple Multiple Products Race Condition Vulnerability
A race condition caused by improper locking (CWE-667) in Apple's operating systems could allow local privilege escalation. The flaw is triggered by a malicious application already running on the device that exploits a timing race; exploitation requires only low local privileges and no user interaction, though the attack complexity is rated high. A successful attacker gains elevated privileges with high impact to the confidentiality, integrity, and availability of the device. Users of iPhone, iPad, Mac, Apple Watch, and Apple TV running versions earlier than iOS/iPadOS 14.4, macOS Big Sur 11.2 (or the 2021-001 security updates for Catalina and Mojave), watchOS 7.3, and tvOS 14.4 are affected. Apple reported the issue as actively exploited in the wild, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and no public proof-of-concept is known.
What to do: Upgrade to iOS/iPadOS 14.4, watchOS 7.3, and tvOS 14.4; on Macs, upgrade to macOS Big Sur 11.2 or apply Security Update 2021-001 for Catalina and Mojave. As an interim mitigation, avoid installing untrusted applications, since exploitation requires a malicious local app. This vulnerability is in the CISA KEV catalog, so organizations subject to the required action should verify that all managed Apple devices are running the patched versions.
| Apple iPhone OS (iOS) | versions prior to iOS 14.4 |
| Apple iPadOS | versions prior to iPadOS 14.4 |
| Apple macOS Big Sur | versions prior to macOS Big Sur 11.2 |
| Apple macOS Catalina | versions prior to Security Update 2021-001 |
| Apple macOS Mojave | versions prior to Security Update 2021-001 |
| Apple watchOS | versions prior to watchOS 7.3 |
| Apple tvOS | versions prior to tvOS 14.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, mac os x, macos, tvos, watchos
- Weakness
- CWE-667
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H