CVE-2021-30886Use After Free in Apple IOS AND Ipados

CWE-416Use After Free5 documents2 sources
Severity
7.8HIGHNVD
EPSS
0.6%
top 30.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateOct 25

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. An application may be able to execute arbitrary code with kernel privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages11 packages

Appleapple/macos_monterey12.0.1
NVDapple/tvos< 15.1
CVEListV5apple/macosunspecified12.0+2
NVDapple/macos< 12.0.1
NVDapple/ipados< 15.1

📋Vendor Advisories

4
Apple
CVE-2021-30886: macOS Monterey 12.0.12021-10-25
Apple
CVE-2021-30886: tvOS 15.12021-10-25
Apple
CVE-2021-30886: watchOS 8.12021-10-25
Apple
CVE-2021-30886: iOS 15.1 and iPadOS 15.12021-10-25