Vulnerability record · CVE-2021-1782 · published 2 April 2021
CVE-2021-1782: Apple Multiple Products Race Condition Privilege Escalation
Apple · Ipados
A race condition in Apple's macOS, iOS, iPadOS, watchOS and tvOS was addressed with improved locking. A malicious application can exploit the race to elevate privileges, and Apple stated it was aware of a report that the issue may have been actively exploited.
Description
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a locally exploitable privilege escalation with confirmed active exploitation and KEV listing, though it requires the attacker to already run code on the device.
What it is
A race condition in Apple's macOS, iOS, iPadOS, watchOS and tvOS was addressed with improved locking. A malicious application can exploit the race to elevate privileges, and Apple stated it was aware of a report that the issue may have been actively exploited.
Impact
An attacker who can run a malicious application on a vulnerable device gains elevated privileges, potentially reaching kernel-level or higher-integrity code execution.
Attack surface
The flaw is local (CVSS vector AV:L) and requires the attacker to run a malicious application on the target device; no user interaction beyond launching that app is needed, and low privileges are sufficient (PR:L).
Exploitation
The vulnerability is listed in CISA KEV with a 2021-11-17 remediation due date, and Apple acknowledged reports of active exploitation; EPSS 30-day probability is about 2.2 percent.
What to do
- Apply the vendor updates: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4.
- Enforce a minimum OS baseline across managed Apple devices and block or flag devices below the fixed versions.
- Restrict installation of untrusted or sideloaded applications on managed endpoints to reduce the local attack path.
- Monitor CISA KEV guidance and confirm remediation by the 2021-11-17 due date for federal and regulated environments.
Detection
- Alert on unexpected privilege transitions or processes spawning with elevated integrity from user-writable locations.
- Hunt for anomalous application behavior consistent with local privilege escalation, such as unusual kernel or system service interactions.
- Track OS build versions in endpoint inventory and report devices still below the fixed releases.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-1782 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apple Multiple Products Race Condition Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT212146 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212147 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212148 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212149 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212146 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212147 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212148 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212149 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1782 | US Government Resource |
Track CVE-2021-1782 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-1782), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.