State Issues in macOS - CVE-2021-30904

 

State Issues in macOS - CVE-2021-30904

Published: December 8, 2021


Vulnerability identifier: #VU58676
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30904
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists in the iMessage due to software continues to sync even after successful log out. This leads to message being sent to the system where the user was previously logged in.


Affected software

macOS

How to mitigate CVE-2021-30904

Install updates from vendor's website.

macOS - update to 12.0.1 21A559

External References

Related Security Bulletins