ZeroHour

CVE-2021-30657

KEVmass

Actively Exploited Gatekeeper Bypass in Apple macOS

CISA: Apple macOS Unspecified Vulnerability

CVSS 3.1
5.5 medium
EPSS
69%p99
Published
()
KEV added
AI analysis

CVE-2021-30657 is a logic flaw (CWE-862) in macOS whose faulty state management allows a malicious application to bypass Gatekeeper, Apple's mechanism that verifies and prompts users before first launch of downloaded software. It is triggered locally when a user opens a malicious, quarantined application; the flawed state handling lets the app launch without the expected Gatekeeper authorization checks. An attacker gains the ability to run unsigned or unnotarized code without the usual security warning, which in observed campaigns enabled adware families such as AdLoad to install on user-level accounts. Any Mac running a version of macOS Big Sur prior to 11.3, or macOS Catalina without Security Update 2021-002, is affected. Apple confirmed the issue was being actively exploited in the wild, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Upgrade to macOS Big Sur 11.3 or later, or apply Security Update 2021-002 Catalina (or newer) per Apple's instructions, then verify the installed version under Apple menu > About This Mac. Because the flaw lets quarantined apps launch without a Gatekeeper prompt, scrutinize downloaded applications and monitor for AdLoad adware indicators on endpoints that have not yet been patched. This CVE is in CISA KEV, so federal and KEV-tracked environments must apply the vendor updates by the required action deadline.

Affected
apple macOS Big Surall versions prior to 11.3
apple macOS Catalina (Mac OS X)all versions prior to Security Update 2021-002 Catalina
Estimated exposure
mass≈100M+ Macs running affected Big Sur or Catalina builds at the time of disclosure — macOS held roughly 15-20% of the global desktop OS market, implying an installed base in the hundreds of millions, most of which ran Big Sur or Catalina builds lacking the 11.3/2021-002 fixes in mid-2021.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
mac os x, macos
Weakness
CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news