CVE-2021-30860

HIGH KEV

Apple iOS/iPadOS/macOS - Integer Overflow in PDF Processing

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-30860 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including jeffssh, Levilutz.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-30860, a JBIG2-based vulnerability in iOS. The exploit leverages heap manipulation and bitwise operations to achieve arbitrary code execution, with detailed constants and encoded payloads for the attack.

Description

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Exploits (2)

nomisec WORKING POC 100 stars
by jeffssh · poc
https://github.com/jeffssh/CVE-2021-30860

This repository contains a functional exploit for CVE-2021-30860, a JBIG2-based vulnerability in iOS. The exploit leverages heap manipulation and bitwise operations to achieve arbitrary code execution, with detailed constants and encoded payloads for the attack.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: iOS (JBIG2 decoder, likely in WebKit or PDF rendering)
No auth needed
Prerequisites: Target device running vulnerable iOS version (likely 14.4 or earlier) · Ability to deliver malicious JBIG2-encoded content (e.g., via PDF or webpage)
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER 11 stars
by Levilutz · poc
https://github.com/Levilutz/CVE-2021-30860

This repository provides a scanner to detect evidence of past exploitation of CVE-2021-30860 (FORCEDENTRY) on macOS and iOS devices. It checks for malicious PDF/PSD files disguised as GIFs and SQL database inconsistencies left by the NSO Group's exploit.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Apple macOS (11.0+), iOS (backups)
No auth needed
Prerequisites: Access to macOS/iOS device or unencrypted iPhone backup · Python 3.9+ · iPhone backup tools (for iOS scans)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (16)

Core 16
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212804
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212805
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212807
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212806
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/28
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/27
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/25
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/26
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/40
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/38
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/39
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT212824
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Sep/50
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/09/02/11
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202209-21

Scores

CVSS v3 7.8
EPSS 0.7197
EPSS Percentile 98.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-09-07
InTheWild.io 2021-09-13
ENISA EUVD EUVD-2021-17777
CWE
CWE-190
Status published
Products (8)
apple/ipados < 14.8
apple/iphone_os < 12.5.5
apple/mac_os_x 10.15.7 (7 CPE variants)
apple/mac_os_x 10.15 - 10.15.7
apple/macos < 11.6
apple/watchos < 7.6.2
freedesktop/poppler < 22.09.0
xpdfreader/xpdf < 4.04
Published Aug 24, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026