A new zero-day is being exploited to compromise Macs (CVE-2021-30869)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1789 | Type Confusion RCE in Apple WebKit (iOS, macOS, Safari, tvOS, watchOS) CVE-2021-1789 is a type confusion flaw (CWE-843) in the WebKit engine that powers Safari and web views across Apple's platforms, fixed through improved state handling. An attacker triggers it by getting a victim to open or view maliciously crafted web content, for example via a crafted link in an email or a compromised webpage. Successful exploitation leads to arbitrary code execution in the context of the application rendering the content, and the CVSS 3.1 score of 8.8 reflects high confidentiality, integrity and availability impact with network attack vector and user interaction required. Everyone running affected Apple software below the February 2021 patch levels is exposed — iOS/iPadOS before 14.4, macOS Big Sur before 11.2, macOS Catalina/Mojave without Security Update 2021-001, tvOS before 14.4, watchOS before 7.3, and Safari before 14.0.3 — as well as WebKitGTK users on Fedora per the CPE data. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-05-04) and was used as a macOS zero-day in watering-hole attacks on Hong Kong pro-democracy users, deploying the DazzleSpy backdoor; EPSS estimates a 14.5% chance of exploitation in the next 30 days. Do: Update to iOS/iPadOS 14.4, macOS Big Sur 11.2 (or apply Security Update 2021-001 on Catalina/Mojave), Safari 14.0.3, tvOS 14.4 and watchOS 7.3; on Fedora, apply the available webkitgtk package update. Because this flaw is in CISA KEV and used in targeted watering-hole attacks, prioritize patching internet-facing and high-risk user fleets. Confirm inventory shows no Apple devices below these patch levels and that users are not relying on outdated Safari builds on unsupported macOS versions. | 8.8 | 14% | KEV |
| masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch) plus WebKitGTK-based Linux browsers/apps | |
| CVE-2021-30858 +1 in the same advisory: …30869 | Use-After-Free in WebKit on Apple iOS, iPadOS, and macOS Allows Arbitrary Code Execution CVE-2021-30858 is a use-after-free memory corruption flaw (CWE-416) in the web content processing component (WebKit) of Apple iOS, iPadOS, and macOS, which Apple addressed with improved memory management. An attacker triggers it by getting a victim to process maliciously crafted web content, typically by visiting or being redirected to an attacker-controlled site, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 8.8 High, network vector with user interaction required). Anyone running affected builds of iOS, iPadOS, or macOS, or the affected component on Fedora or Debian Linux per the CPE data, is exposed, since virtually all Apple devices process web content by default. Apple acknowledged that the flaw was being actively exploited, reportedly as part of NSO Group's 'ForcedEntry' targeted zero-day espionage chain, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. No public proof-of-concept is known, but the confirmed in-the-wild use makes rapid patching urgent. Do: Update iPhones and iPads to iOS/iPadOS 14.8 and Macs to macOS Big Sur 11.6 immediately, and on Fedora or Debian apply the distribution's updated WebKit packages. Use MDM or inventory data to confirm no managed devices remain on pre-patch builds, since the flaw was exploited as a zero-day in targeted espionage operations. This is a CISA KEV entry (added 2021-11-03), so the catalog's required action of applying vendor updates is mandatory for federal agencies and strongly recommended for everyone else. | 8.8 group max | 13% | KEV |
| mass>1 billion users/devices (Apple's 1B+ active device base, all of which carry the vulnerable web-content code path) | |
| CVE-2021-30860 | Integer Overflow in Apple PDF Processing Enables Arbitrary Code Execution (CVE-2021-30860) CVE-2021-30860 is an integer overflow (CWE-190) in PDF processing across Apple's platforms that was addressed with improved input validation. It is triggered when a device processes a maliciously crafted PDF — notably when a PDF is rendered after being received via messaging — and successful exploitation allows arbitrary code execution in the context of the PDF renderer. Affected products include iOS/iPadOS, macOS (Big Sur and Catalina), and watchOS, as well as the Xpdf and Poppler PDF libraries, which share lineage with the vulnerable code. Apple confirmed the issue was being actively exploited in the wild, and public reporting ties it to NSO Group's 'ForcedEntry' exploit chain used to deliver Pegasus spyware; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. Given the very high EPSS score (76%, 99th percentile) and confirmed active exploitation, defenders should treat this as a high-priority patch. Do: Update iPhones/iPads to iOS/iPadOS 14.8, Macs to macOS Big Sur 11.6 (or apply Security Update 2021-005 Catalina), and Apple Watch to watchOS 7.6.2 immediately, and patch Poppler/Xpdf through distribution or vendor updates. Because the flaw was exploited via crafted PDFs delivered through messaging (ForcedEntry/Pegasus), organizations and individuals at risk of targeted spyware should also review devices for signs of compromise. CISA KEV requires applying updates per vendor instructions; prioritize internet-connected and high-value user endpoints. | 7.8 | 76% | KEV |
| mass>1 billion active Apple devices (iPhones, iPads, Macs, Apple Watches), plus Poppler present by default on most Linux desktops and servers |
Full article314 words · extracted from helpnetsecurity.com · click to collapse
Another zero-day in Apple’s software (CVE-2021-30869) is being actively exploited by attackers, forcing the company to push out security updates for macOS Catalina and iOS 12.

About CVE-2021-30869
Flagged by researchers Erye Hernandez and Clément Lecigne of Google’s Threat Analysis Group and Ian Beer of Google Project Zero, the vulnerability is a type confusion issue found in XNU, the kernel of Apple’s macOS and iOS operating systems.
As usual, Apple did not share any details about the flaw, and said only that it allows a malicious application to execute arbitrary code with kernel privileges.
Another Google TAG threat analyst shared that CVE-2021-30869 is being exploited in conjunction with a previously known WebKit vulnerabilities, and said that more details will be released after 30 days.
0day privilege escalation for macOS Catalina discovered in the wild by @eryeh https://t.co/yvCWPo45fL
We saw this used in conjunction with a N-day remote code execution targeting webkit.
Thanks to Apple for getting patch out so quickly.
— Shane Huntley (@ShaneHuntley) September 23, 2021
The iOS 12.5.5 security update also contains fixes for CVE-2021-30860 – the “zero-click” iMessage vulnerability exploited to deliver spyware that was patched in newer versions of iOS ten days ago – and CVE-2021-30858 – an actively exploited RCE in WebKit.
UPDATE (November 12, 2021, 06:58 a.m. PT):
Google’s Threat Analysis Group has shared details about the attacks leveraging CVE-2021-30869.
They were watering hole attacks and the targets were visitors of Hong Kong websites for a media outlet and a pro-democracy labor and political group.
Two iframes inserted into the websites served exploits chains for macOS and iOS. The former combined an RCE in WebKit (CVE-2021-1789) patched on Jan 5, and CVE-2021-30869. The final payload was a previously unknown backdoor.
The macOS exploit chain did not work on macOS Big Sur (11.4), because apparently “Apple added generic protections in Big Sur which rendered this exploit useless.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/09/24/cve-2021-30869/