⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..
Severity
7.8HIGH
EPSS
70.6%
top 1.31%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 24
KEV addedNov 3
KEV dueNov 17
Latest updateApr 1
CISA Required Action: Apply updates per vendor instructions.

Description

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

CVEListV5apple/macosunspecified11.6+1
NVDapple/macos< 11.6
NVDapple/ipados< 14.8
CVEListV5apple/watchosunspecified7.6
NVDapple/watchos< 7.6.2

🔴Vulnerability Details

4
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
Project0
A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution - Project Zero2021-12-01
CVEList
CVE-2021-30860: An integer overflow was addressed with improved input validation2021-08-24
VulnCheck
Apple Multiple Products Integer Overflow Vulnerability2021

📋Vendor Advisories

6
CISA
Apple Multiple Products Integer Overflow Vulnerability2021-11-03
Apple
CVE-2021-30860: iOS 12.5.52021-09-23
Apple
CVE-2021-30860: macOS Big Sur 11.62021-09-13
Apple
CVE-2021-30860: watchOS 7.6.22021-09-13
Apple
CVE-2021-30860: Security Update 2021-005 Catalina2021-09-13
CVE-2021-30860 (HIGH CVSS 7.8) | An integer overflow was addressed w | cvebase.io