CVE-2021-30804 describes a permissions issue in Apple iOS that, if exploited by a malicious application, could allow unauthorized access to Find My data. This vulnerability, affecting iPhone devices running iOS versions prior to 14.7, has a low CVSS score of 3.3, indicating a local attack vector with user interaction required and a low impact on integrity. While the vulnerability has been patched in iOS 14.7, there is no public exploit code available, nor is it listed in CISA's KEV catalog, suggesting it is not actively exploited. Community discussion and media coverage are minimal, with only one article from Threatpost mentioning it in the context of other Apple updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.7CPE match | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.