Race condition in macOS - CVE-2021-30955
Published: December 14, 2021 / Updated: June 29, 2022
Vulnerability identifier: #VU58867
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30955
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in the OS kernel. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
macOS
watchOS
tvOS
Apple iOS
iPadOS
watchOS
tvOS
Apple iOS
iPadOS
How to mitigate CVE-2021-30955
Install updates from vendor's website.
macOS - update to 12.1 21C52
watchOS - update to 8.3 19S55
tvOS - update to 15.2 19K53
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56
watchOS - update to 8.3 19S55
tvOS - update to 15.2 19K53
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56
Links to Public Exploits and PoC-codes
- Exploit #8092 - desc_race (desc_race exploit for iOS 15.0 - 15.1.1 (with stable kernel r/w primitives) (CVE-2021-30955) ) (June 29, 2022)
- Exploit #7520 - Pentagram-exploit-tester (A test app to check if your device is vulnerable to CVE-2021-30955) (March 20, 2022)
- Exploit #7502 - desc_race_A15 (CVE-2021-30955 iOS 15.1.1 POC for 6GB RAM devices (A14-A15)) (March 16, 2022)
- Exploit #7416 - CVE-2021-30955-POC-IPA (https://gist.github.com/jakeajames/37f72c58c775bfbdda3aa9575149a8aa compiled into a ipa 15.0-15.2b1) (March 5, 2022)
- Exploit #7402 - desc_race (iOS 15.1 kernel exploit POC for CVE-2021-30955) (March 1, 2022)