7.8
CVSSv3

CVE-2021-30774

Published: 08/09/2021 Updated: 11/02/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 829
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. A malicious application may be able to gain root privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple mac os x 10.15.7

apple watchos

apple tvos

apple iphone os

apple macos

apple ipados

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-1 iOS 147 and iPadOS 147 iOS 147 and iPadOS 147 addresses the following issues Information about the security content is also available at supportapplecom/HT212601 iOS 147 released July 19, 2021; iPadOS 147 released July 21, 2021 ActionKit Available for: iPhon ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-2 macOS Big Sur 115 macOS Big Sur 115 addresses the following issues Information about the security content is also available at supportapplecom/HT212602 AMD Kernel Available for: macOS Big Sur Impact: An application may be able to execute arbitrary code with kerne ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-6 tvOS 147 tvOS 147 addresses the following issues Information about the security content is also available at supportapplecom/HT212604 Audio Available for: Apple TV 4K and Apple TV HD Impact: A local attacker may be able to cause unexpected application termination ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-07-21-5 watchOS 76 watchOS 76 addresses the following issues Information about the security content is also available at supportapplecom/HT212605 ActionKit Available for: Apple Watch Series 3 and later Impact: A shortcut may be able to bypass Internet permission requirem ...

Github Repositories

iService: Detecting and Evaluating the Impact of Confused Deputy Problem in AppleOS (ACSAC'22)

iService Overview iService is a static analysis framework to detect confused deputies in system services in AppleOS Specifically, It resolves Objective-C Messages using the top-down type propagation and performs data dependence analysis to identify input validations of sensitive operations iService discovered 11 confused deputies, of which 5 were 0-day bugs with CVE numbers a

A Static Dataflow Analysis Framework for iOS Applications.

AegiScan Aegi(s)Scan(er) is a static dataflow analysis framework for iOS application binaries, which can be used to facilitate vulnerability scanning Overview Design AegiScan utilizes top-down type propagation to resolve Objective-C MsgSend calls, thereby reconstructing the call graph It then generates the Code Property Graph (CPG) for each function to establish context-sensi