Race condition in macOS - CVE-2021-30995

 

Race condition in macOS - CVE-2021-30995

Published: December 14, 2021 / Updated: February 16, 2022


Vulnerability identifier: #VU58876
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30995
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition in the Preferences feature. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

macOS
watchOS
tvOS
Apple iOS
iPadOS

How to mitigate CVE-2021-30995

Install updates from vendor's website.

macOS - addressed in versions 12.1 21C52, 10.15.7 19H1615, 11.6.2 20G314
watchOS - update to 8.3 19S55
tvOS - update to 15.2 19K53
Apple iOS - addressed in versions 15.2 19C56, 15.2 19C57
iPadOS - update to 15.2 19C56

External References

Related Security Bulletins