support.apple.com
https://support.apple.com/en-us/HT212846 CVE-2021-30883
HIGHCISA KEV
Apple Multiple Products Memory Corruption Vulnerability
Record summary
CVE-2021-30883 has a selected CVSS score of 7.8 (high). CISA lists CVE-2021-30883 in KEV.
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · May 23, 2022 · CISA
- VulnCheck KEV
- Listed · Oct 11, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 15.0 | affected |
| Before 14.8 | affected | ||
macOSBrowse Apple / macOS | CVE List | Before 12.0 | affected |
| Before 11.6 | affected | ||
| Before 8.1 | affected | ||
| Before 15.1 | affected | ||
References
7support.apple.com
https://support.apple.com/en-us/HT212868 support.apple.com
https://support.apple.com/en-us/HT212869 support.apple.com
https://support.apple.com/en-us/HT212872 support.apple.com
https://support.apple.com/en-us/HT212874 support.apple.com
https://support.apple.com/en-us/HT212876 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30883