CVE-2021-30768 is a logic issue affecting Apple's iOS, macOS, watchOS, and tvOS that allows a sandboxed process to bypass security restrictions due to insufficient validation. With a CVSS score of 5.5 (Medium), this vulnerability requires user interaction (UI:R) and local access (AV:L), potentially leading to high integrity impact (I:H). While not listed in CISA's KEV catalog, and with no public exploit code available in Metasploit, Nuclei, or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness of the flaw. Apple addressed this vulnerability in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7, and Security Update 2021-004 Catalina.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.7CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 10.15, <= 10.15.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.