Race condition in iPadOS and Apple iOS - CVE-2021-30857

 

Race condition in iPadOS and Apple iOS - CVE-2021-30857

Published: September 20, 2021


Vulnerability identifier: #VU56724
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30857
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition with the OS kernel component. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

iPadOS
Apple iOS
watchOS
macOS
tvOS

How to mitigate CVE-2021-30857

Install updates from vendor's website.

iPadOS - update to 15.0 19A346
Apple iOS - update to 15.0 19A346
watchOS - update to 8.0 19R346
macOS - addressed in versions 10.15.7 19H1417, 11.6 20G165
tvOS - update to 15.0 19J346

External References

Related Security Bulletins