Race condition in iPadOS and Apple iOS - CVE-2021-30857
Published: September 20, 2021
Vulnerability identifier: #VU56724
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30857
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition with the OS kernel component. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
iPadOS
Apple iOS
watchOS
macOS
tvOS
Apple iOS
watchOS
macOS
tvOS
How to mitigate CVE-2021-30857
Install updates from vendor's website.
iPadOS - update to 15.0 19A346
Apple iOS - update to 15.0 19A346
watchOS - update to 8.0 19R346
macOS - addressed in versions 10.15.7 19H1417, 11.6 20G165
tvOS - update to 15.0 19J346
Apple iOS - update to 15.0 19A346
watchOS - update to 8.0 19R346
macOS - addressed in versions 10.15.7 19H1417, 11.6 20G165
tvOS - update to 15.0 19J346