Race condition in macOS - CVE-2021-30996
Published: December 14, 2021
Vulnerability identifier: #VU58860
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30996
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition within the IOMobileFrameBuffer subsystem. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
macOS
iPadOS
Apple iOS
iPadOS
Apple iOS
How to mitigate CVE-2021-30996
Install updates from vendor's website.
macOS - update to 12.1 21C52
iPadOS - update to 15.2 19C56
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57