CVE-2021-30750Incorrect Default Permissions in Apple Macos

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 65.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 8
Latest updateMay 24

Description

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5apple/macosunspecified11.3
NVDapple/macos11.011.3

🔴Vulnerability Details

1
GHSA
GHSA-9cjg-xfcq-56f3: The issue was addressed with improved permissions logic2022-05-24

📋Vendor Advisories

1
Apple
CVE-2021-30750: macOS Big Sur 11.32021-04-26