ZeroHour

CVE-2021-30900

KEVmass

Kernel Out-of-Bounds Write in Apple iOS, iPadOS, and macOS (Actively Exploited)

CISA: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

CVSS 3.1
7.8 high
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2021-30900 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS, iPadOS, and macOS, addressed by Apple with improved bounds checking. It is triggered locally when a user runs a malicious application crafted to exploit the flaw (CVSS local vector with user interaction required). Successful exploitation allows the attacker to execute arbitrary code with kernel privileges, effectively yielding full control of the device. Anyone running an affected build is exposed: iOS/iPadOS versions prior to 14.8.1 and 15.1, plus macOS builds listed in Apple's advisory. The bug has been exploited in the wild in commercial spyware campaigns observed by Google TAG in Italy, Malaysia, Kazakhstan, and the UAE, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30 (EPSS 5.2%, 92nd percentile; ransomware use unknown).

What to do: Update devices to iOS/iPadOS 14.8.1 or 15.1 (or later) and apply the corresponding macOS security update per Apple's instructions, consistent with CISA's KEV required action. Inventory mobile fleets via MDM for devices still on older builds and prioritize remediation where spyware campaigns in Italy, Malaysia, Kazakhstan, or the UAE are relevant, checking device logs for signs of compromise since these exploit chains often bundle additional flaws.

Affected
Apple iPhone OS (iOS)iOS versions prior to 14.8.1 (14.x line) and prior to 15.1 (15.x line); fixed in iOS 14.8.1 and iOS 15.1
Apple iPadOSiPadOS versions prior to 14.8.1 (14.x line) and prior to 15.1 (15.x line); fixed in iPadOS 14.8.1 and iPadOS 15.1
Apple macOS
Estimated exposure
mass≈1B+ Apple devices (active iPhone/iPad/Mac installed base) — Apple's combined active iPhone, iPad, and Mac installed base exceeds one billion devices per public company disclosures, and pre-14.8.1/15.1 builds accounted for a large share of that base when the fix shipped, so plausible exposure is on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A malicious application may be able to execute arbitrary code with kernel privileges.

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news