CVE-2021-30902Use After Free in Apple IOS AND Ipados

CWE-416Use After Free4 documents3 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 77.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateOct 26

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A local attacker may be able to cause unexpected application termination or arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDapple/ipad_os< 14.8.1
CVEListV5apple/ios_and_ipadosunspecified15.1+1
NVDapple/ipados15.0
NVDapple/iphone_os< 14.8.1+1

🔴Vulnerability Details

1
CVEList
CVE-2021-30902: A use after free issue was addressed with improved memory management2021-08-24

📋Vendor Advisories

2
Apple
CVE-2021-30902: iOS 14.8.1 and iPadOS 14.8.12021-10-26
Apple
CVE-2021-30902: iOS 15.1 and iPadOS 15.12021-10-25
CVE-2021-30902 — Use After Free in Apple IOS AND Ipados | cvebase