CVE-2021-30860
Apple macOS, Apple watchOS, Apple iOS
Published 24 Aug 2021 · updated 17 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 17 Nov 2021 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
References
- seclists.org/fulldisclosure/2021/Sep/25 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2021/Sep/26 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2021/Sep/27 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2021/Sep/28 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2021/Sep/38 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2021/Sep/39 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2021/Sep/40 · Mailing List, Third Party Advisory
- seclists.org/fulldisclosure/2021/Sep/50 · Mailing List, Third Party Advisory
- www.openwall.com/lists/oss-security/2022/09/02/11 · Mailing List
- security.gentoo.org/glsa/202209-21 · Third Party Advisory
- support.apple.com/en-us/HT212804 · Vendor Advisory
- support.apple.com/en-us/HT212805 · Vendor Advisory
- support.apple.com/en-us/HT212806 · Vendor Advisory
- support.apple.com/en-us/HT212807 · Vendor Advisory
- support.apple.com/kb/HT212824 · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30860 · US Government Resource