CVE-2021-30860 is an integer overflow vulnerability affecting Apple products (iOS, iPadOS, macOS, watchOS) and other software utilizing Xpdf's JBIG2 implementation, allowing arbitrary code execution through maliciously crafted PDFs. With a CVSS score of 7.8 (High), it presents a significant risk due to its high impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. This vulnerability is actively exploited in the wild, notably by Pegasus spyware, and has garnered substantial community and media attention, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.8CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 12.5.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 13.0, < 14.8CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.15, < 10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.