Vulnerability record · CVE-2021-30807 · published 19 October 2021
CVE-2021-30807: Apple macOS, iOS, iPadOS and watchOS out-of-bounds write in kernel
Apple · Ipados
CVE-2021-30807 is an out-of-bounds write (CWE-787) memory corruption issue in Apple's kernel, fixed in macOS Big Sur 11.5.1, iOS 14.7.1, iPadOS 14.7.1 and watchOS 7.6.1. Apple states it is aware of a report that the issue may have been actively exploited, so unpatched devices are at real risk. The record does not name the specific kernel component or the affected code path.
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a kernel-level arbitrary code execution flaw with confirmed in-the-wild exploitation per CISA KEV, but it requires local access and user interaction, which limits mass exploitation.
What it is
CVE-2021-30807 is an out-of-bounds write (CWE-787) memory corruption issue in Apple's kernel, fixed in macOS Big Sur 11.5.1, iOS 14.7.1, iPadOS 14.7.1 and watchOS 7.6.1. Apple states it is aware of a report that the issue may have been actively exploited, so unpatched devices are at real risk. The record does not name the specific kernel component or the affected code path.
Impact
A successful exploit lets an application execute arbitrary code with kernel privileges, giving the attacker full control of the device.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the attacker must get a victim to open or run a crafted application or file on the target device. No remote or unauthenticated network path is described.
Exploitation
The vulnerability is listed in CISA KEV (added 2021-11-03) and Apple states it may have been actively exploited; EPSS 30-day probability is 0.28839 (98th percentile). No ransomware campaign use is documented.
What to do
- Update to macOS Big Sur 11.5.1, iOS 14.7.1, iPadOS 14.7.1 or watchOS 7.6.1 or later as applicable, per Apple advisories HT212622, HT212623 and HT212713.
- Prioritize patching internet-facing and high-value Apple devices, and treat the KEV due date of 2021-11-17 as the remediation deadline for covered US federal systems.
- Restrict users from opening untrusted applications, documents or attachments until devices are patched.
- Inventory Apple endpoints and confirm version levels so unpatched macOS, iOS, iPadOS and watchOS devices are identified.
- Monitor vendor advisories for any further updates if the affected component is later clarified.
Detection
- Hunt for unexpected kernel-level code execution or crashes on Apple endpoints, since the flaw is a kernel memory corruption.
- Review endpoint telemetry for unusual application behavior preceding kernel panics or privilege escalation.
- Check patch and version compliance data for macOS, iOS, iPadOS and watchOS against the fixed releases.
- Correlate any known exploitation reporting with device logs, though the record provides no specific indicators of compromise.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30807 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apple Multiple Products Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT212622 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212623 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212713 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212622 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212623 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212713 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30807 | Third Party AdvisoryUS Government Resource |
Track CVE-2021-30807 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30807), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.