Vulnerability record · CVE-2021-30713 · published 8 September 2021
CVE-2021-30713: Apple macOS privacy preference bypass via missing authorization
Apple · Mac Os X
macOS Big Sur before 11.4 has a permissions validation flaw (CWE-862 missing authorization) that lets a malicious application bypass Privacy preferences. Apple states it is aware of a report that this issue may have been actively exploited, so it matters as a local privilege and privacy control bypass on affected Macs.
Description
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with reported active exploitation and high CVSS impact, though it requires local access and low privileges rather than being remotely exploitable.
What it is
macOS Big Sur before 11.4 has a permissions validation flaw (CWE-862 missing authorization) that lets a malicious application bypass Privacy preferences. Apple states it is aware of a report that this issue may have been actively exploited, so it matters as a local privilege and privacy control bypass on affected Macs.
Impact
A local attacker running a malicious app can bypass macOS Privacy (TCC) preferences, gaining access to protected user data and resources that should require explicit consent. The CVSS vector indicates high confidentiality, integrity and availability impact within the local context.
Attack surface
Reached locally: the CVSS vector is AV:L with PR:L and UI:N, so the attacker needs local access and low privileges but no user interaction. No network vector or authentication bypass over the network is described.
Exploitation
Listed in CISA KEV with a 2021-11-03 addition and 2021-11-17 remediation due date, and Apple states it may have been actively exploited; EPSS 30-day probability is about 7 percent (93.9th percentile). No ransomware campaign use is documented.
What to do
- Update macOS to Big Sur 11.4 or later per Apple advisories HT212529 and HT212805.
- Restrict local execution of untrusted applications and enforce application allowlisting on managed Macs.
- Review and tighten Privacy/TCC permissions and monitor for unexpected changes to protected resource access.
- Apply the CISA KEV required action and track remediation against the 2021-11-17 due date.
- Audit local admin and standard user accounts to limit who can run arbitrary code on endpoints.
Detection
- Monitor for unexpected or unauthorized modifications to TCC/Privacy preference databases on macOS endpoints.
- Alert on processes accessing protected resources (camera, microphone, screen recording, files) without a corresponding user consent record.
- Hunt for execution of untrusted or unsigned applications from user-writable directories on macOS hosts.
- Correlate endpoint telemetry with Apple security update status to find unpatched Big Sur systems below 11.4.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30713 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apple macOS Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2021/Sep/40 | Mailing ListThird Party Advisory |
| https://support.apple.com/en-us/HT212529 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT212805 | Release NotesVendor Advisory |
| http://seclists.org/fulldisclosure/2021/Sep/40 | Mailing ListThird Party Advisory |
| https://support.apple.com/en-us/HT212529 | Release NotesVendor Advisory |
| https://support.apple.com/kb/HT212805 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30713 | Third Party AdvisoryUS Government Resource |
Track CVE-2021-30713 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30713), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.