⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..

CVE-2021-30869Type Confusion in Apple IOS AND Ipados

CWE-843Type Confusion19 documents8 sources
Severity
7.8HIGHNVD
EPSS
1.7%
top 17.57%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedAug 24
KEV addedNov 3
KEV dueNov 17
Latest updateJan 9
CISA Required Action: Apply updates per vendor instructions.

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5apple/macosunspecified11.2+2
NVDapple/macos11.011.2
NVDapple/ipados< 14.4
CVEListV5apple/ios_and_ipadosunspecified14.4
NVDapple/mac_os_x10.1410.14.6+3

🔴Vulnerability Details

3
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
CVEList
CVE-2021-30869: A type confusion issue was addressed with improved state handling2021-08-24
VulnCheck
Apple iOS, iPadOS, and macOS Type Confusion Vulnerability2021

📋Vendor Advisories

5
CISA
Apple iOS, iPadOS, and macOS Type Confusion Vulnerability2021-11-03
Apple
CVE-2021-30869: iOS 12.5.52021-09-23
Apple
CVE-2021-30869: Security Update 2021-006 Catalina2021-09-23
Apple
CVE-2021-30869: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave2021-02-01
Apple
CVE-2021-30869: iOS 14.4 and iPadOS 14.42021-01-26

🕵️Threat Intelligence

10
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise2023-01-09
Sentinelone
7 Ways Threat Actors Deliver macOS Malware in the Enterprise2023-01-09
Sentinelone
How SysJoker and DazzleSpy Malware Target macOS2022-02-01
Sentinelone
How SysJoker and DazzleSpy Malware Target macOS2022-02-01
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-012021-11-09
CVE-2021-30869 — Type Confusion in Apple IOS AND Ipados | cvebase