CVE-2021-30657
KEVmassActively Exploited Gatekeeper Bypass in Apple macOS
CISA: Apple macOS Unspecified Vulnerability
CVE-2021-30657 is a logic flaw (CWE-862) in macOS whose faulty state management allows a malicious application to bypass Gatekeeper, Apple's mechanism that verifies and prompts users before first launch of downloaded software. It is triggered locally when a user opens a malicious, quarantined application; the flawed state handling lets the app launch without the expected Gatekeeper authorization checks. An attacker gains the ability to run unsigned or unnotarized code without the usual security warning, which in observed campaigns enabled adware families such as AdLoad to install on user-level accounts. Any Mac running a version of macOS Big Sur prior to 11.3, or macOS Catalina without Security Update 2021-002, is affected. Apple confirmed the issue was being actively exploited in the wild, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade to macOS Big Sur 11.3 or later, or apply Security Update 2021-002 Catalina (or newer) per Apple's instructions, then verify the installed version under Apple menu > About This Mac. Because the flaw lets quarantined apps launch without a Gatekeeper prompt, scrutinize downloaded applications and monitor for AdLoad adware indicators on endpoints that have not yet been patched. This CVE is in CISA KEV, so federal and KEV-tracked environments must apply the vendor updates by the required action deadline.
| apple macOS Big Sur | all versions prior to 11.3 |
| apple macOS Catalina (Mac OS X) | all versions prior to Security Update 2021-002 Catalina |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- mac os x, macos
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N