CVE-2021-30925Incorrect Authorization in Apple Macos

Severity
9.1CRITICALNVD
EPSS
0.2%
top 53.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateSep 20

Description

The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages9 packages

CVEListV5apple/macosunspecified11.6+1
NVDapple/macos< 11.6
NVDapple/ipados< 15.0
CVEListV5apple/watchosunspecified8
NVDapple/watchos< 8.0

📋Vendor Advisories

3
Apple
CVE-2021-30925: iOS 15 and iPadOS 152021-09-20
Apple
CVE-2021-30925: watchOS 82021-09-20
Apple
CVE-2021-30925: macOS Big Sur 11.62021-09-13