Buffer overflow in iPadOS and Apple iOS - CVE-2021-30838
Published: September 20, 2021
Vulnerability identifier: #VU56716
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30838
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the Accessory Manager. A local application can trigger memory corruption and execute arbitrary code with system privileges on devices with an Apple Neural Engine
Affected software
iPadOS
Apple iOS
macOS
Apple iOS
macOS
How to mitigate CVE-2021-30838
Install updates from vendor's website.
iPadOS - update to 15.0 19A346
Apple iOS - update to 15.0 19A346
macOS - update to 11.6 20G165
Apple iOS - update to 15.0 19A346
macOS - update to 11.6 20G165