Race condition in macOS - CVE-2021-30652

 

Race condition in macOS - CVE-2021-30652

Published: April 27, 2021


Vulnerability identifier: #VU52621
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30652
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition within the libxpc library. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

macOS
watchOS
iPadOS
tvOS
Apple iOS

How to mitigate CVE-2021-30652

Install updates from vendor's website.

macOS - addressed in versions 10.14.6 18G9028, 10.15.7 19H1030, 11.3 20E232
watchOS - update to 7.4 18T195
iPadOS - update to 14.5 18E199
tvOS - update to 14.5 18L204
Apple iOS - update to 14.5 18E199

External References

Related Security Bulletins