CVE-2021-30657

MEDIUM KEV

macOS Gatekeeper check bypass

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2021-30657 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including shubham0d, Cedric Owens, timwr, Ferdous Saljooki, Jaron Bradley, Mickey Jin, Shelby Pace, including a Metasploit module exploits/osx/browser/osx_gatekeeper_bypass.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2021-30657, which bypasses macOS security features like Gatekeeper and File Quarantine by crafting a malicious application bundle. The exploit generates a DMG file that, when executed by the victim, runs an arbitrary payload script without triggering security checks.

Description

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

Exploits (2)

nomisec WORKING POC 30 stars
by shubham0d · local
https://github.com/shubham0d/CVE-2021-30657

This repository contains a functional proof-of-concept exploit for CVE-2021-30657, which bypasses macOS security features like Gatekeeper and File Quarantine by crafting a malicious application bundle. The exploit generates a DMG file that, when executed by the victim, runs an arbitrary payload script without triggering security checks.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: macOS Big Sur < 11.3, Security Update Catalina < 2021-002
No auth needed
Prerequisites: Victim must download and execute the crafted DMG file
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC MANUAL
by Cedric Owens, timwr, Ferdous Saljooki, Jaron Bradley, Mickey Jin, Shelby Pace · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/browser/osx_gatekeeper_bypass.rb

This Metasploit module exploits CVE-2021-30657 and CVE-2022-22616 to bypass macOS Gatekeeper by serving a maliciously crafted ZIP file. The exploit leverages missing Info.plist or gzip compression to evade quarantine checks, allowing arbitrary payload execution.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: macOS < 11.3 (CVE-2021-30657) and macOS < 12.3 (CVE-2022-22616)
No auth needed
Prerequisites: User interaction (download and execute the malicious ZIP) · Safari browser for automatic extraction in CVE-2022-22616
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212325
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212326

Scores

CVSS v3 5.5
EPSS 0.6853
EPSS Percentile 99.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-26
InTheWild.io 2021-09-08
ENISA EUVD EUVD-2021-17574
CWE
CWE-862
Status published
Products (4)
apple/mac_os_x 10.15.6 (2 CPE variants)
apple/mac_os_x 10.15.7 (6 CPE variants)
apple/mac_os_x 10.15 - 10.15.5
apple/macos 11.0 - 11.3
Published Sep 08, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026