CVE-2021-1870 is a critical logic issue affecting Apple's macOS, iOS, and iPadOS that could allow a remote attacker to achieve arbitrary code execution. With a CVSS score of 9.8, this vulnerability is easily exploitable over a network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Apple has confirmed active exploitation in the wild, and while public exploit code is not available, the vulnerability has garnered significant community discussion and media attention, indicating its high profile and potential threat. Organizations should prioritize patching to macOS Big Sur 11.2, Security Update 2021-001 Catalina/Mojave, and iOS/iPadOS 14.4 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.4CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 14.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.15, < 10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.