CVE-2021-32847 describes a host memory disclosure vulnerability in HyperKit versions 0.20210107 and prior, affecting the mobyproject hyperkit. A malicious guest operating system can exploit a flaw in the disk driver to leak host memory into the virtualized guest. This is a medium severity vulnerability (CVSS 6.5) requiring local access to the guest (AV:L, PR:L) with low attack complexity (AC:L), leading to high confidentiality impact (C:H). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.20210107CPE matchmatch criteria | cpe:2.3:a:mobyproject:hyperkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.