CVE-2021-30657

MEDIUM KEV

macOS Gatekeeper check bypass

Title source: metasploit

Description

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

Exploits (2)

nomisec WORKING POC 30 stars
by shubham0d · local
https://github.com/shubham0d/CVE-2021-30657
metasploit WORKING POC MANUAL
by Cedric Owens, timwr, Ferdous Saljooki, Jaron Bradley, Mickey Jin, Shelby Pace · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/browser/osx_gatekeeper_bypass.rb

Scores

CVSS v3 5.5
EPSS 0.8308
EPSS Percentile 99.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-26
InTheWild.io 2021-09-08
ENISA EUVD EUVD-2021-17574
CWE
CWE-862
Status published
Products (4)
apple/macos 11.0 - 11.3
apple/mac_os_x 10.15.6 (2 CPE variants)
apple/mac_os_x 10.15.7 (6 CPE variants)
apple/mac_os_x 10.15 - 10.15.5
Published Sep 08, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026