CVE-2021-30892
published 2021-08-24CVE-2021-30892: An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina…
PriorityP430medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
10.35%
95.2th percentile
An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to modify protected parts of the file system.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.15.7 | 10.15.7 |
| apple | mac_os_x | — | — |
| apple | macos | — | — |
| apple | macos | >= 11.0 < 11.6.1 | 11.6.1 |
| apple | macos | >= unspecified < 12.0 | 12.0 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2021-007_catalina | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-30892: macOS Monterey 12.0.1
vendor_apple·2021-10-25·CVSS 5.5
CVE-2021-30892 [MEDIUM] CVE-2021-30892: macOS Monterey 12.0.1
Apple Security Update: About the security content of macOS Monterey 12.0.1
Product: macOS Monterey
Version: 12.0.1
CVE: CVE-2021-30892
Component: Windows Server
Impact: A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen
Description: An authentication issue was addressed with improved state management.
Apple
CVE-2021-30892: macOS Big Sur 11.6.1
vendor_apple·2021-10-25·CVSS 5.5
CVE-2021-30892 [MEDIUM] CVE-2021-30892: macOS Big Sur 11.6.1
Apple Security Update: About the security content of macOS Big Sur 11.6.1
Product: macOS Big Sur
Version: 11.6.1
CVE: CVE-2021-30892
Component: Windows Server
Impact: A local attacker may be able to view the previous logged-in user’s desktop from the fast user switching screen
Description: An authentication issue was addressed with improved state management.
Apple
CVE-2021-30892: Security Update 2021-007 Catalina
vendor_apple·2021-10-25·CVSS 5.5
CVE-2021-30892 [MEDIUM] CVE-2021-30892: Security Update 2021-007 Catalina
Apple Security Update: About the security content of Security Update 2021-007 Catalina
Product: Security Update 2021-007 Catalina
CVE: CVE-2021-30892
Component: UIKit
Impact: A person with physical access to a device may be able to determine characteristics of a user's password in a secure text entry field
Description: A logic issue was addressed with improved state management.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
blogs_bleepingcomputer·2025-07-28·CVSS 7.1
CVE-2020-9771 [HIGH] Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
## Sergiu Gatlan
Since 2020, Apple has patched other TCC bypasses that exploit Time Machine mounts ( CVE-2020-9771 ), environment variable poisoning ( CVE-2020-9934 ), and a bundle conclusion issue ( CVE-2021-30713 ) . In the past, Microsoft security researchers have also discovered several other TCC bypasses, including powerdir ( CVE-2021-30970 ) and HM-Surf , that could also be abused to gain access to users' private data.
"While similar to prior TCC bypasses like HM-Surf and powerdir, the implications of this vulnerability, which we refer to as 'Sploitlight' for its use of Spotlight plugins, are more severe due to its ability to extract and leak sensitive information cached by Apple Intelligence, such as precise geol
Bleepingcomputer
Microsoft: macOS bug lets hackers install malicious kernel drivers
blogs_bleepingcomputer·2025-01-13·CVSS 5.5
CVE-2024-44243 [MEDIUM] Microsoft: macOS bug lets hackers install malicious kernel drivers
## Microsoft: macOS bug lets hackers install malicious kernel drivers
## Sergiu Gatlan
"System Integrity Protection (SIP) serves as a critical safeguard against malware, attackers, and other cybersecurity threats, establishing a fundamental layer of protection for macOS systems," Microsoft said today in a report that provides more technical details on CVE-2024-44243.
"Bypassing SIP impacts the entire operating system's security and could lead to severe consequences, emphasizing the necessity for comprehensive security solutions that can detect anomalous behavior from specially entitled processes."
Microsoft security researchers have discovered multiple macOS vulnerabilities in recent years. A SIP bypass dubbed 'Shrootless ' ( CVE-2021-30892 ), reported in 2021, also allows attackers to
Checkpoint
1st November – Threat Intelligence Report
blogs_checkpoint·2021-11-01
CVE-2021-34484 1st November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
A cyberattack has disrupted gasoline sale in Iran. Fueling machines showed a message saying “cyberattack 64411”, the number being the phone number for the office of Iran’s Supreme Leader, and a reference to the attack on Iran’s railway system attributed to the Indra attack group.
The North Korean threat group Lazarus (AK
2021-08-24
Published