CVE-2026-30867 is a medium-severity vulnerability affecting iOS/macOS/tvOS applications using the CocoaMQTT client library prior to version 2.2.2. A remote attacker or malicious MQTT broker can exploit this by publishing a malformed MQTT packet with the RETAIN flag, leading to a persistent denial of service where vulnerable applications crash immediately upon subscription. This effectively "bricks" the mobile application until the retained message is manually cleared from the broker. With a CVSS score of 5.7, there is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.2CPE matchmatch criteria | cpe:2.3:a:emqx:cocoamqtt:*:*:*:*:*:swift:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.