CVE-2021-30869: Apple iOS, iPadOS, and macOS Type Confusion Vulnerability
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
Other sources
Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
— CISA
XNU. A type confusion issue was addressed with improved state handling.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 12.5.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
macOS Big Surto a version that resolves this vulnerability.Fixed in 11.2 - Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Patch Security Update 2021-001 Catalina - Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Patch Security Update 2021-006 Catalina - Upgrade
Upgrade
macOS Mojaveto a version that resolves this vulnerability.Patch Security Update 2021-001 Mojave
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30869
- CVE-2021-1761
- CVE-2021-1797
- CVE-2020-27945
- CVE-2021-1760
- CVE-2021-1747
- CVE-2021-1776
- CVE-2021-1759
- CVE-2021-1772
- CVE-2021-1792
- CVE-2021-1787
- CVE-2021-1786
- CVE-2020-27937
- CVE-2021-1802
- CVE-2021-1791
- CVE-2021-1790
- CVE-2021-1775
- CVE-2020-29608
- CVE-2021-1758
- CVE-2021-1783
- CVE-2021-1741
- CVE-2021-1743
- CVE-2021-1773
- CVE-2021-1778
- CVE-2021-1736
- CVE-2021-1785
- CVE-2021-1766
- CVE-2021-1818
- CVE-2021-1742
- CVE-2021-1746
- CVE-2021-1754
- CVE-2021-1774
- CVE-2021-1777
- CVE-2021-1793
- CVE-2021-1737
- CVE-2021-1738
- CVE-2021-1744
- CVE-2021-1779
- CVE-2021-1757
- CVE-2020-27904
- CVE-2021-1764
- CVE-2021-1782
- CVE-2021-1750
- CVE-2020-29633
- CVE-2021-1781
- CVE-2021-1771
- CVE-2021-1762
- CVE-2020-29614
- CVE-2021-1763
- CVE-2021-1767
- CVE-2021-1745
- CVE-2021-1753
- CVE-2021-1768
- CVE-2021-1751
- CVE-2020-25709
- CVE-2020-27938
- CVE-2019-20838
- CVE-2020-14155
- CVE-2020-15358
- CVE-2021-1769
- CVE-2021-1788
- CVE-2021-1765
- CVE-2021-1801
- CVE-2021-1789
- CVE-2021-1871
- CVE-2021-1870
- CVE-2021-1799
- CVE-2021-30860
- CVE-2021-31010
- CVE-2021-30858
- CVE-2021-1794
- CVE-2021-1795
- CVE-2021-1796
- CVE-2021-1780
- CVE-2021-1838
- CVE-2021-1748
- CVE-2021-1756
Frequently Asked Questions
What is CVE-2021-30869?
CVE-2021-30869 is a type confusion vulnerability in Apple iOS, iPadOS, and macOS that may allow a malicious application to execute code with kernel privileges.
Which Apple software is affected by CVE-2021-30869?
Apple iOS, iPadOS, and macOS are affected by CVE-2021-30869.
How can a malicious application exploit CVE-2021-30869?
A malicious application can exploit CVE-2021-30869 to execute code with kernel privileges.
What is the severity of CVE-2021-30869?
The severity of CVE-2021-30869 is not specified.
How can I fix CVE-2021-30869?
To fix CVE-2021-30869, update to the recommended versions of Apple iOS, iPadOS, and macOS.