CVE-2021-30784 is a high-severity vulnerability affecting macOS Big Sur versions prior to 11.5, allowing a local attacker to execute code on the Apple T2 Security Chip due to improved logic issues. With a CVSS score of 7.8, it presents a significant risk (FAUCET Risk Score 59/100) as it permits high impact to confidentiality, integrity, and availability with low attack complexity. While there is no evidence of active exploitation (not in KEV) and no public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.5CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 10.14.0, < 10.14.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
>= 10.15, < 10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.14.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.14.6:-:*:*:*:*:*:* | ||
10.14.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.14.6:security_update_2019-001:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.