ZeroHour

CVE-2021-30807

KEVmass

Memory Corruption in Apple iOS, iPadOS, macOS, watchOS Allows Kernel Code Execution

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
29%p98
Published
()
KEV added
AI analysis

A memory corruption flaw (out-of-bounds write, CWE-787) exists in Apple's IOMobileFrameBuffer component, a core graphics/frame-buffer interface shared across iOS, iPadOS, macOS, and watchOS. It is triggered by an application running on the device interacting with the frame buffer interface, which corrupts kernel memory. Successful exploitation may allow the application to execute arbitrary code with kernel privileges, giving the attacker full control of the device and bypassing normal app sandboxing. Any device running an unpatched version of iOS, iPadOS, macOS, or watchOS is affected, which spans essentially the entire Apple device fleet. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild, and EPSS assigns a 28.8% probability of exploitation within 30 days (98th percentile); no public PoC is known.

What to do: Apply Apple's current software updates for iOS, iPadOS, macOS, and watchOS on all managed devices per vendor instructions, prioritizing internet-facing and corporate-owned iPhones, iPads, and Macs. Use MDM/endpoint inventory to identify devices on outdated OS builds and verify patch compliance, noting CISA added this flaw to the KEV catalog on 2021-11-03 with required action to apply updates per vendor instructions.

Affected
Apple iOS
Apple iPadOS
Apple macOS
Apple watchOS
Estimated exposure
mass≈1 billion+ active Apple devices (core OS component present across the iOS/iPadOS/macOS/watchOS install base); number actually exploited unknown — The flaw sits in IOMobileFrameBuffer, a core component present in essentially every iOS, iPadOS, macOS, and watchOS device, and Apple's publicly stated active install base exceeds one billion devices, so the theoretical exposure upper…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news