ZeroHour

CVE-2021-30860

KEVmass

Integer Overflow in Apple PDF Processing Enables Arbitrary Code Execution (CVE-2021-30860)

CISA: Apple Multiple Products Integer Overflow Vulnerability

CVSS 3.1
7.8 high
EPSS
76%p100
Published
()
KEV added
AI analysis

CVE-2021-30860 is an integer overflow (CWE-190) in PDF processing across Apple's platforms that was addressed with improved input validation. It is triggered when a device processes a maliciously crafted PDF — notably when a PDF is rendered after being received via messaging — and successful exploitation allows arbitrary code execution in the context of the PDF renderer. Affected products include iOS/iPadOS, macOS (Big Sur and Catalina), and watchOS, as well as the Xpdf and Poppler PDF libraries, which share lineage with the vulnerable code. Apple confirmed the issue was being actively exploited in the wild, and public reporting ties it to NSO Group's 'ForcedEntry' exploit chain used to deliver Pegasus spyware; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. Given the very high EPSS score (76%, 99th percentile) and confirmed active exploitation, defenders should treat this as a high-priority patch.

What to do: Update iPhones/iPads to iOS/iPadOS 14.8, Macs to macOS Big Sur 11.6 (or apply Security Update 2021-005 Catalina), and Apple Watch to watchOS 7.6.2 immediately, and patch Poppler/Xpdf through distribution or vendor updates. Because the flaw was exploited via crafted PDFs delivered through messaging (ForcedEntry/Pegasus), organizations and individuals at risk of targeted spyware should also review devices for signs of compromise. CISA KEV requires applying updates per vendor instructions; prioritize internet-connected and high-value user endpoints.

Affected
Apple iPhone OS (iOS)versions prior to iOS 14.8 (fixed in iOS 14.8)
Apple iPadOSversions prior to iPadOS 14.8 (fixed in iPadOS 14.8)
Apple macOS Catalinafixed by Security Update 2021-005 Catalina
Apple macOS Big Surversions prior to 11.6 (fixed in macOS Big Sur 11.6)
Apple watchOSversions prior to 7.6.2 (fixed in watchOS 7.6.2)
XpdfReader (xpdfreader) Xpdf
freedesktop.org Poppler
Estimated exposure
mass>1 billion active Apple devices (iPhones, iPads, Macs, Apple Watches), plus Poppler present by default on most Linux desktops and servers — Apple's publicly reported active install base exceeds one billion iPhones plus tens of millions of Macs and Apple Watches, and Poppler ships as the default PDF rendering library in major Linux distributions, so the potentially exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
applexpdfreaderfreedesktop
Products
ipados, iphone os, mac os x, macos, watchos, xpdf, poppler
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news