CVE-2021-30713
published 2021-09-08CVE-2021-30713: A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy…
PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
6.58%
93.1th percentile
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | 10.15 – 10.15.7 | — |
| apple | macos | < 11.4 | 11.4 |
| apple | macos | >= unspecified < 11.4 | 11.4 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-005_catalina | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor macOS endpoint security events for TCC permission modifications using the ES_EVENT_TYPE_NOTIFY_TCC_MODIFY identifier (macOS 15.4+) to detect TCC bypass attempts related to this CVE. ↗
- ·The vulnerability is in the TCC component of macOS; the exact bypass mechanism is described as 'unspecified' by CISA, and Apple only states it is 'a permissions issue addressed with improved validation' — no further technical primitives are disclosed in these sources. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple macOS Unspecified Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2021-30713 [HIGH] CWE-862 Apple macOS Unspecified Vulnerability
Vulnerability: Apple macOS Unspecified Vulnerability
Affected: Apple macOS
Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30713
Remediation Due Date: 2021-11-17
Apple
CVE-2021-30713: Security Update 2021-005 Catalina
vendor_apple·2021-09-13·CVSS 7.8
CVE-2021-30713 [HIGH] CVE-2021-30713: Security Update 2021-005 Catalina
Apple Security Update: About the security content of Security Update 2021-005 Catalina
Product: Security Update 2021-005 Catalina
CVE: CVE-2021-30713
Component: TCC
Impact: A malicious application may be able to bypass Privacy preferences
Description: A permissions issue was addressed with improved validation.
Apple
CVE-2021-30713: macOS Big Sur 11.4
vendor_apple·2021-05-24·CVSS 7.8
CVE-2021-30713 [HIGH] CVE-2021-30713: macOS Big Sur 11.4
Apple Security Update: About the security content of macOS Big Sur 11.4
Product: macOS Big Sur
Version: 11.4
CVE: CVE-2021-30713
Component: TCC
Impact: A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited.
Description: A permissions issue was addressed with improved validation.
GHSA
GHSA-x3vf-fcq8-6cpg: A permissions issue was addressed with improved validation
ghsa_unreviewed·2022-05-24
CVE-2021-30713 [HIGH] CWE-20 GHSA-x3vf-fcq8-6cpg: A permissions issue was addressed with improved validation
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..
VulnCheck
Apple macOS Unspecified Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-30713 [HIGH] CWE-862 Apple macOS Unspecified Vulnerability
Apple macOS Unspecified Vulnerability
Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.
Affected: Apple MacOS X
Required Action: Apply updates per vendor instructions.
Exploitation References: https://support.apple.com/kb/HT212529; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.huntress.com/blog/say-hello-to-mac-malware-a-tradecraft-tuesday-recap
Remediation Due: 2021-11-17
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
blogs_bleepingcomputer·2025-07-28·CVSS 7.1
CVE-2020-9771 [HIGH] Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Sergiu Gatlan
Since 2020, Apple has patched other TCC bypasses that exploit Time Machine mounts ( CVE-2020-9771 ), environment variable poisoning ( CVE-2020-9934 ), and a bundle conclusion issue ( CVE-2021-30713 ) . In the past, Microsoft security researchers have also discovered several other TCC bypasses, including powerdir ( CVE-2021-30970 ) and HM-Surf , that could also be abused to gain access to users' private data.
"While similar to prior TCC bypasses like HM-Surf and powerdir, the implications of this vulnerability, which we refer to as 'Sploitlight' for its use of Spotlight plugins, are more severe due to its ability to extract and leak sensitive information cached by Apple Intelligence, such as precise geol
Huntress
Say Hello to Mac Malware
blogs_huntress·2025-04-22
Say Hello to Mac Malware
Yes, Windows devices are still very much a business favorite—but the adoption of macOS devices has been steadily ticking upward. Threat actors have noticed.
More macOS malware variants have cropped up over the years, ranging from frustrating adware (like Adload) to insidious spyware (like LightSpy ). The LockBit ransomware group has even dabbled with a macOS ransomware variant .
Apple has taken several steps over the years to build security measures into its platform , including Gatekeeper and the Transparency Consent and Control (TCC) framework. These features help end users better manage access to their sensitive data and can help detect malware lurking on their systems—but threat actors are also continually finetuning their attacks to get around them.
In our recent April Tradecraft T
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Checkpoint
31st May – Threat Intelligence Report
blogs_checkpoint·2021-05-31
CVE-2020-7200 31st May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 31st May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has conducted a joint investigation into an ongoing and highly targeted campaign against China’s Uyghur minority, using messages and sites impersonating UN and human rights groups. The attackers deployed malware capable of exfiltrating information and gaining control of victim PCs.
The Russian-based hackers
Huntress
Say Hello to Mac Malware | Huntress
blogs_huntress
Say Hello to Mac Malware | Huntress
Yes, Windows devices are still very much a business favorite—but the adoption of macOS devices has been steadily ticking upward. Threat actors have noticed.
More macOS malware variants have cropped up over the years, ranging from frustrating adware (like Adload) to insidious spyware (like LightSpy). The LockBit ransomware group has even dabbled with a macOS ransomware variant.
Apple has taken several steps over the years to build security measures into its platform, including Gatekeeper and the Transparency Consent and Control (TCC) framework. These features help end users better manage access to their sensitive data and can help detect malware lurking on their systems—but threat actors are also continually finetuning their attacks to get around them.
In our recent April Tradecraft Tues
http://seclists.org/fulldisclosure/2021/Sep/40https://support.apple.com/en-us/HT212529https://support.apple.com/kb/HT212805http://seclists.org/fulldisclosure/2021/Sep/40https://support.apple.com/en-us/HT212529https://support.apple.com/kb/HT212805https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30713
2021-09-08
Published
2021-11-03
Added to CISA KEV
Exploited in the wild