CVE-2021-30869
KEVmassType Confusion in Apple iOS, iPadOS and macOS Allows Kernel Code Execution
CISA: Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
CVE-2021-30869 is a type confusion flaw (CWE-843) in the kernel of Apple's iOS, iPadOS, and macOS operating systems, addressed with improved state handling. It is triggered locally when a user runs a malicious application, which can then leverage the memory-type confusion to escape the app sandbox context. Successful exploitation gives the attacker arbitrary code execution with kernel privileges, effectively full control of the device. Users of iPhone, iPad, and Mac running versions released before the January 2021 fixes are affected. Apple has confirmed exploits exist in the wild, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and news reporting linked exploitation to targeted attacks against macOS users in Hong Kong.
What to do: Upgrade to iOS 14.4 (or iOS 12.5.5 for older devices), iPadOS 14.4, or macOS Big Sur 11.2, and apply Security Update 2021-001 Catalina or Security Update 2021-001 Mojave (Security Update 2021-006 Catalina also addresses the issue) on Macs. Because exploitation requires running a malicious application, remove untrusted apps and warn users against installing software from unverified sources while patching. This flaw is on the CISA KEV list, so federal and KEV-committed organizations must apply the updates per vendor instructions; no public proof-of-concept is known.
| Apple iPhone OS (iOS) | iOS versions prior to 14.4; iOS 12.x prior to 12.5.5 |
| Apple iPadOS | iPadOS versions prior to 14.4 |
| Apple macOS Big Sur | macOS Big Sur versions prior to 11.2 |
| Apple macOS Catalina | macOS 10.15 Catalina prior to Security Update 2021-001 Catalina (also addressed in Security Update 2021-006 Catalina) |
| Apple macOS Mojave | macOS 10.14 Mojave prior to Security Update 2021-001 Mojave |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
- Affected
- Apple iOS, iPadOS, and macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, mac os x, macos
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H