CVE-2021-30713

HIGH KEV

macOS Big Sur <11.4 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-30713 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021.

Description

A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..

References (4)

Core 4
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212529
Release Notes, Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT212805
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/40

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 23.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-05-24
InTheWild.io 2021-07-21
ENISA EUVD EUVD-2021-17630
CWE
CWE-862
Status published
Products (3)
apple/mac_os_x 10.15.7 (9 CPE variants)
apple/mac_os_x 10.15 - 10.15.7
apple/macos < 11.4
Published Sep 08, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026