ZeroHour

CVE-2021-30869

KEVmass

Type Confusion in Apple iOS, iPadOS and macOS Allows Kernel Code Execution

CISA: Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2021-30869 is a type confusion flaw (CWE-843) in the kernel of Apple's iOS, iPadOS, and macOS operating systems, addressed with improved state handling. It is triggered locally when a user runs a malicious application, which can then leverage the memory-type confusion to escape the app sandbox context. Successful exploitation gives the attacker arbitrary code execution with kernel privileges, effectively full control of the device. Users of iPhone, iPad, and Mac running versions released before the January 2021 fixes are affected. Apple has confirmed exploits exist in the wild, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and news reporting linked exploitation to targeted attacks against macOS users in Hong Kong.

What to do: Upgrade to iOS 14.4 (or iOS 12.5.5 for older devices), iPadOS 14.4, or macOS Big Sur 11.2, and apply Security Update 2021-001 Catalina or Security Update 2021-001 Mojave (Security Update 2021-006 Catalina also addresses the issue) on Macs. Because exploitation requires running a malicious application, remove untrusted apps and warn users against installing software from unverified sources while patching. This flaw is on the CISA KEV list, so federal and KEV-committed organizations must apply the updates per vendor instructions; no public proof-of-concept is known.

Affected
Apple iPhone OS (iOS)iOS versions prior to 14.4; iOS 12.x prior to 12.5.5
Apple iPadOSiPadOS versions prior to 14.4
Apple macOS Big SurmacOS Big Sur versions prior to 11.2
Apple macOS CatalinamacOS 10.15 Catalina prior to Security Update 2021-001 Catalina (also addressed in Security Update 2021-006 Catalina)
Apple macOS MojavemacOS 10.14 Mojave prior to Security Update 2021-001 Mojave
Estimated exposure
masshundreds of millions of devices (Apple's active installed base of iPhones, iPads, and Macs is on the order of 1 billion devices, and pre-patch OS versions were… — Estimate based on Apple's publicly known installed base of roughly a billion active iOS/iPadOS/macOS devices and the broad prevalence of pre-14.4 iOS, pre-11.2 Big Sur, and unpatched Catalina/Mojave builds when the fix shipped, making the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, mac os x, macos
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news