CVE-2021-30881
HIGHiPadOS < 15.1 - Remote Code Execution via Malicious Archive
Title source: llmDescription
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. Unpacking a maliciously crafted archive may lead to arbitrary code execution.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212869
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212871
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212872
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212867
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212874
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212876
Scores
CVSS v3
7.8
EPSS
0.0121
EPSS Percentile
64.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (8)
apple/ipados
< 15.1
apple/iphone_os
< 15.1
apple/mac_os_x
10.15.7 (9 CPE variants)
apple/mac_os_x
< 10.15.7
apple/macos
12.0
apple/macos
11.0 - 11.6.1
apple/tvos
< 15.1
apple/watchos
< 8.1
Published
Aug 24, 2021
Tracked Since
Feb 18, 2026