Type Confusion in macOS - CVE-2021-30869
Published: September 23, 2021 / Updated: September 24, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a type confusion error within the XNU subsystem. A local user can run a specially crafted program to trigger a type confusion error and execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apple iOS
iPadOS
How to mitigate CVE-2021-30869
Apple iOS - addressed in versions 12.5.5 16H62, 14.4 18D52
iPadOS - update to 14.4 18D52