CVE-2021-30943

MEDIUM

iPadOS < 15.2 - Insufficient Session Expiration in Messages Group Handling

Title source: llm
STIX 2.1

Description

An issue in the handling of group membership was resolved with improved logic. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1. A malicious user may be able to leave a messages group but continue to receive messages in that group.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212975
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212976
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212978

Scores

CVSS v3 4.3
EPSS 0.0076
EPSS Percentile 50.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-613
Status published
Products (4)
apple/ipados < 15.2
apple/iphone_os < 15.2
apple/macos 12.0.0 - 12.1
apple/watchos < 8.3
Published Aug 24, 2021
Tracked Since Feb 18, 2026