ZeroHour
Security Affairspublished ()ingested @securityaffairs

Apple fixes CVE-2021-30807 flaw, the 13th zero

criticalVulnerability exploited in the wildimportance 60CVE-2021-30807

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30807
Memory Corruption in Apple iOS, iPadOS, macOS, watchOS Allows Kernel Code Execution

A memory corruption flaw (out-of-bounds write, CWE-787) exists in Apple's IOMobileFrameBuffer component, a core graphics/frame-buffer interface shared across iOS, iPadOS, macOS, and watchOS. It is triggered by an application running on the device interacting with the frame buffer interface, which corrupts kernel memory. Successful exploitation may allow the application to execute arbitrary code with kernel privileges, giving the attacker full control of the device and bypassing normal app sandboxing. Any device running an unpatched version of iOS, iPadOS, macOS, or watchOS is affected, which spans essentially the entire Apple device fleet. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild, and EPSS assigns a 28.8% probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Apply Apple's current software updates for iOS, iPadOS, macOS, and watchOS on all managed devices per vendor instructions, prioritizing internet-facing and corporate-owned iPhones, iPads, and Macs. Use MDM/endpoint inventory to identify devices on outdated OS builds and verify patch compliance, noting CISA added this flaw to the KEV catalog on 2021-11-03 with required action to apply updates per vendor instructions.

7.829% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
  • +1 more
mass≈1 billion+ active Apple devices (core OS component present across the iOS/iPadOS/macOS/watchOS install base); number actually exploited unknown
Full article211 words · extracted from securityaffairs.com · click to collapse

Apple released a security update that addresses CVE-2021-30807 flaw in macOS and iOS that may have been actively exploited to deliver malware

Apple addressed a security flaw, tracked as CVE-2021-30807, in macOS and iOS that may have been actively exploited to plant malware on vulnerable devices. The vulnerability resides in the IOMobileFramebuffer, which is a kernel extension for managing the screen framebuffer. It is controlled by the user-land framework IOMobileFramework.

The IT giant did not publish details about the attacks either the attackers that exploited the vulnerability.

An attacker could trigger the CVE-2021-30807 to execute arbitrary code with kernel privileges on a vulnerable device.

Attackers could exploit the flaw to take full control over a device.

“An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.” reads the advisory published by Apple.

Apple addressed the memory corruption issue by improving memory handling.

This is the 13th zero-day flaw fixed by Apple this year:

Apple addressed the flaw with the release of macOS Big Sur 11.5.1, iOS 14.7.1, and iPadOS 14.7.1, versions.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, APT41)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/120576/security/apple-cve-2021-30807-zero-day.html