CVE-2021-30833 is a medium-severity vulnerability affecting Apple macOS that allows an attacker to write arbitrary files by tricking a user into unpacking a maliciously crafted archive. The attack requires user interaction (UI:R) and local access (AV:L), but has low attack complexity (AC:L). While not actively exploited (KEV: No) and lacking public exploit code, it garnered significant community discussion and media coverage, indicating awareness. This issue was addressed with improved checks in macOS Monterey 12.0.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 10.15, < 10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020:*:*:*:*:*:* | ||
10.15.7CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.