CVE-2021-30858
HIGH KEViOS <14.8-iPadOS <14.8-macOS Big Sur <11.6 - Use After Free
Title source: llmExploitation Summary
CVE-2021-30858 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including kmeps4, Jeromeyoung.
AI-analyzed exploit summary The repository contains only a README.md referencing CVE-2021-30858 without any functional exploit code or technical analysis. It links to an external post but provides no additional details or proof-of-concept.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Exploits (2)
The repository contains only a README.md referencing CVE-2021-30858 without any functional exploit code or technical analysis. It links to an external post but provides no additional details or proof-of-concept.
The repository contains only a README and a Jekyll config file with no actual exploit code or technical details. It claims to be a PoC for CVE-2021-30858 but lacks any functional implementation.
References (19)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H