Skip to content
COOEY

EXPOSURES › CVE-2021-30900

CVE-2021-30900

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-03-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30900 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

Apple iOS, iPadOS, and macOS had an unpatched RCE flaw exploited in the wild

Apple's iOS, iPadOS, and macOS had a critical out-of-bounds write vulnerability that allowed malicious apps to execute with kernel privileges, enabling remote code execution. This was actively exploited and not patched, posing a significant risk to DIB organizations.

Shame score — Critical unpatched RCE flaw actively exploited in the wild

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.