Exploitation Summary
CVE-2021-30657 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021.
EIP tracks 2 public exploits from researchers including shubham0d, Cedric Owens, timwr, Ferdous Saljooki, Jaron Bradley, Mickey Jin, Shelby Pace, including a Metasploit module exploits/osx/browser/osx_gatekeeper_bypass.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2021-30657, which bypasses macOS security features like Gatekeeper and File Quarantine by crafting a malicious application bundle. The exploit generates a DMG file that, when executed by the victim, runs an arbitrary payload script without triggering security checks.
Description
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..
Exploits (2)
This repository contains a functional proof-of-concept exploit for CVE-2021-30657, which bypasses macOS security features like Gatekeeper and File Quarantine by crafting a malicious application bundle. The exploit generates a DMG file that, when executed by the victim, runs an arbitrary payload script without triggering security checks.
This Metasploit module exploits CVE-2021-30657 and CVE-2022-22616 to bypass macOS Gatekeeper by serving a maliciously crafted ZIP file. The exploit leverages missing Info.plist or gzip compression to evade quarantine checks, allowing arbitrary payload execution.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N