Input validation error in macOS - CVE-2021-30833
Published: October 27, 2021 / Updated: February 16, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input when processing xar archives. A remote attacker can create a specially crafted .xar archive, trick the victim into opening it and overwrite arbitrary files on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Affected software
Gentoo Linux
app-arch/xar
How to mitigate CVE-2021-30833
app-arch/xar - update to 1.8.0.0.487.100.1