CVE-2021-30859Type Confusion in Apple Macos

CWE-843Type Confusion5 documents3 sources
Severity
7.8HIGHNVD
EPSS
0.3%
top 49.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateSep 13

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5apple/macosunspecified11.6+2
NVDapple/macos11.011.6
NVDapple/ipados< 14.8
NVDapple/mac_os_x< 10.15.7+1
NVDapple/iphone_os< 14.8

🔴Vulnerability Details

1
CVEList
CVE-2021-30859: A type confusion issue was addressed with improved state handling2021-08-24

📋Vendor Advisories

3
Apple
CVE-2021-30859: macOS Big Sur 11.62021-09-13
Apple
CVE-2021-30859: Security Update 2021-005 Catalina2021-09-13
Apple
CVE-2021-30859: iOS 14.8 and iPadOS 14.82021-09-13
CVE-2021-30859 — Type Confusion in Apple Macos | cvebase