CVE-2021-30860
Last modified
CVE-2021-30860 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. CISA has confirmed active exploitation in the wild. EPSS estimates a 75.99% chance of exploitation in the next 30 days.
Description
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Ipados | < 14.8 |
| Apple | Iphone Os | < 12.5.5 |
| Apple | Iphone Os | >= 13.0, < 14.8 |
| Apple | Mac Os X | >= 10.15, < 10.15.7 |
| Apple | Mac Os X | 10.15.7 |
| Apple | Macos | < 11.6 |
| Apple | Watchos | < 7.6.2 |
| Xpdfreader | Xpdf | < 4.04 |
| Freedesktop | Poppler | < 22.09.0 |
References
- https://seclists.org/fulldisclosure/2021/Sep/25Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/26Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/27Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/28Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/38Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/39Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/40Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/50Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202209-21Third Party Advisory
- https://support.apple.com/en-us/HT212804Vendor Advisory
- https://support.apple.com/en-us/HT212805Vendor Advisory
- https://support.apple.com/en-us/HT212806Vendor Advisory
- https://support.apple.com/en-us/HT212807Vendor Advisory
- https://support.apple.com/kb/HT212824Vendor Advisory
- https://seclists.org/fulldisclosure/2021/Sep/25Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/26Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/27Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/28Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/38Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/39Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/40Mailing List, Third Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/50Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202209-21Third Party Advisory
- https://support.apple.com/en-us/HT212804Vendor Advisory
- https://support.apple.com/en-us/HT212805Vendor Advisory
- https://support.apple.com/en-us/HT212806Vendor Advisory
- https://support.apple.com/en-us/HT212807Vendor Advisory
- https://support.apple.com/kb/HT212824Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30860US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-30860?
How severe is CVE-2021-30860?
How do I fix CVE-2021-30860?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-30854A logic issue was addressed with improved state management. …8.6
- CVE-2021-30855A validation issue existed in the handling of symlinks. This…5.5
- CVE-2021-30856This issue was addressed by adding a new Remote Login option…9.1
- CVE-2021-30857A race condition was addressed with improved locking. This i…7
- CVE-2021-30858A use after free issue was addressed with improved memory ma…8.8
- CVE-2021-30859A type confusion issue was addressed with improved state han…7.8
- CVE-2021-30861A logic issue was addressed with improved state management. …5.5
- CVE-2021-30862A validation issue was addressed with improved input sanitiz…6.1
- CVE-2021-30863This issue was addressed by improving Face ID anti-spoofing …6.8
- CVE-2021-30864A logic issue was addressed with improved state management. …8.6
- CVE-2021-30865An out-of-bounds read was addressed with improved input vali…7.8
- CVE-2021-30866A user privacy issue was addressed by removing the broadcast…6.5
Are you affected by CVE-2021-30860?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
