Integer overflow in iPadOS and Apple iOS - CVE-2021-30883
Published: October 12, 2021 / Updated: October 27, 2021
Vulnerability details
The vulnerability allows a malicious application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the IOMobileFrameBuffer subsystem. A malicious application can trigger integer overflow and execute arbitrary code on with kernel privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apple iOS
watchOS
macOS
tvOS
How to mitigate CVE-2021-30883
Apple iOS - addressed in versions 15.0.2 19A404, 14.8.1 18H107
watchOS - update to 8.1 19R570
macOS - addressed in versions 11.6.1 20G224, 12.0.1 21A559
tvOS - update to 15.1 19J572