Buffer overflow in macOS - CVE-2021-30807
Published: July 26, 2021 / Updated: December 30, 2021
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary within the IOMobileFrameBuffer subsystem. A local application can trigger memory corruption and execute arbitrary code on the target system with kernel privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
watchOS
iPadOS
Apple iOS
How to mitigate CVE-2021-30807
watchOS - update to 7.6.1 18U70
iPadOS - update to 14.7.1 18G82
Apple iOS - update to 14.7.1 18G82