EXPOSURES › CVE-2021-30860
CVE-2021-30860
HIGH ⌖ ON CISA KEV · EXPLOITEDApple's CoreGraphics integer overflow vulnerability (CVE-2021-30860) allowed remote code execution via malicious PDFs across iOS, iPadOS, macOS, and watchOS.
This integer overflow flaw in CoreGraphics enabled arbitrary code execution when processing crafted PDFs, directly impacting DIB organizations relying on Apple devices for secure operations. The vulnerability was actively exploited in the wild (KEV), demonstrating that even major vendors can ship unpatched, high-severity flaws that compromise device integrity and violate NIST 800-171 requirements for patch management and vulnerability mitigation.
Shame score — A critical integer overflow flaw affecting core system components was actively exploited in the wild, indicating severe negligence in patch management and vulnerability disclosure for a major DIB vendor.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.
"Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF."