CVE-2021-30860
KEVmassInteger Overflow in Apple PDF Processing Enables Arbitrary Code Execution (CVE-2021-30860)
CISA: Apple Multiple Products Integer Overflow Vulnerability
CVE-2021-30860 is an integer overflow (CWE-190) in PDF processing across Apple's platforms that was addressed with improved input validation. It is triggered when a device processes a maliciously crafted PDF — notably when a PDF is rendered after being received via messaging — and successful exploitation allows arbitrary code execution in the context of the PDF renderer. Affected products include iOS/iPadOS, macOS (Big Sur and Catalina), and watchOS, as well as the Xpdf and Poppler PDF libraries, which share lineage with the vulnerable code. Apple confirmed the issue was being actively exploited in the wild, and public reporting ties it to NSO Group's 'ForcedEntry' exploit chain used to deliver Pegasus spyware; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. Given the very high EPSS score (76%, 99th percentile) and confirmed active exploitation, defenders should treat this as a high-priority patch.
What to do: Update iPhones/iPads to iOS/iPadOS 14.8, Macs to macOS Big Sur 11.6 (or apply Security Update 2021-005 Catalina), and Apple Watch to watchOS 7.6.2 immediately, and patch Poppler/Xpdf through distribution or vendor updates. Because the flaw was exploited via crafted PDFs delivered through messaging (ForcedEntry/Pegasus), organizations and individuals at risk of targeted spyware should also review devices for signs of compromise. CISA KEV requires applying updates per vendor instructions; prioritize internet-connected and high-value user endpoints.
| Apple iPhone OS (iOS) | versions prior to iOS 14.8 (fixed in iOS 14.8) |
| Apple iPadOS | versions prior to iPadOS 14.8 (fixed in iPadOS 14.8) |
| Apple macOS Catalina | fixed by Security Update 2021-005 Catalina |
| Apple macOS Big Sur | versions prior to 11.6 (fixed in macOS Big Sur 11.6) |
| Apple watchOS | versions prior to 7.6.2 (fixed in watchOS 7.6.2) |
| XpdfReader (xpdfreader) Xpdf | — |
| freedesktop.org Poppler | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- applexpdfreaderfreedesktop
- Products
- ipados, iphone os, mac os x, macos, watchos, xpdf, poppler
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H