Record summary

CVE-2021-30807 has a selected CVSS score of 7.8 (high); EIP currently links 2 repository PoCs. CISA lists CVE-2021-30807 in KEV.

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Jul 26, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListBefore 11.5affected
Before 14.7affected
Before 7.6affected

Proofs of concept

2

Repository PoCs

GitHubjsherman212/iomfb-exploitRepository PoCby jsherman212Stars: 133Not analyzed13 files

80.6 KiB

GitHub

PoC details
GitHub30440r/gexRepository PoCby 30440rStars: 5Not analyzed12 files

77.6 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

5