Integer overflow in iPadOS and Apple iOS - CVE-2021-30883

 

Integer overflow in iPadOS and Apple iOS - CVE-2021-30883

Published: October 12, 2021 / Updated: October 27, 2021


Vulnerability identifier: #VU57217
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30883
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a malicious application to escalate privileges on the system.

The vulnerability exists due to a boundary error within the IOMobileFrameBuffer subsystem. A malicious application can trigger integer overflow and execute arbitrary code on with kernel privileges.

Note, the vulnerability is being actively exploited in the wild.




Affected software

iPadOS
Apple iOS
watchOS
macOS
tvOS

How to mitigate CVE-2021-30883

Install updates from vendor's website.

iPadOS - addressed in versions 15.0.2 19A404, 14.8.1 18H107
Apple iOS - addressed in versions 15.0.2 19A404, 14.8.1 18H107
watchOS - update to 8.1 19R570
macOS - addressed in versions 11.6.1 20G224, 12.0.1 21A559
tvOS - update to 15.1 19J572

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins