CVE-2021-30892Incorrect Permission Assignment in Apple Macos

Severity
5.5MEDIUMNVD
EPSS
1.9%
top 16.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 24
Latest updateJul 28

Description

An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to modify protected parts of the file system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5apple/macosunspecified12.0+2
NVDapple/macos11.011.6.1+1
NVDapple/mac_os_x< 10.15.7+1

🔴Vulnerability Details

1
CVEList
CVE-2021-30892: An inherited permissions issue was addressed with additional restrictions2021-08-24

📋Vendor Advisories

3
Apple
CVE-2021-30892: macOS Monterey 12.0.12021-10-25
Apple
CVE-2021-30892: macOS Big Sur 11.6.12021-10-25
Apple
CVE-2021-30892: Security Update 2021-007 Catalina2021-10-25

🕵️Threat Intelligence

2
Bleepingcomputer
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data2025-07-28
Bleepingcomputer
Microsoft: macOS bug lets hackers install malicious kernel drivers2025-01-13
CVE-2021-30892 — Incorrect Permission Assignment | cvebase