Vulnerability record · CVE-2021-30883 · published 24 August 2021
CVE-2021-30883: Apple iOS/iPadOS/macOS/tvOS/watchOS memory corruption kernel code execution
Apple · Ipados
An out-of-bounds write memory corruption flaw in Apple operating systems was fixed with improved memory handling. Successful exploitation lets an application execute arbitrary code with kernel privileges, and Apple stated it was aware of a report that the issue may have been actively exploited.
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed in-the-wild exploitation and KEV listing raise urgency, but the local attack vector and required user interaction keep it below critical.
What it is
An out-of-bounds write memory corruption flaw in Apple operating systems was fixed with improved memory handling. Successful exploitation lets an application execute arbitrary code with kernel privileges, and Apple stated it was aware of a report that the issue may have been actively exploited.
Impact
An attacker who gets a malicious application running on the device can execute arbitrary code at kernel level, effectively taking full control of the underlying OS. That breaks the platform's core security boundary and enables persistent, privileged compromise.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the flaw is reached by running a crafted application on the target device rather than over the network. No authentication is needed, but the victim must trigger the malicious app or content.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-05-23, and Apple's advisory states the issue may have been actively exploited; EPSS gives a 30-day exploitation probability of about 14.7 percent (96th percentile). No ransomware campaign use is documented.
What to do
- Apply the Apple updates that fix this issue: iOS 15.0.2 and iPadOS 15.0.2, iOS 14.8.1 and iPadOS 14.8.1, macOS Monterey 12.0.1, macOS Big Sur 11.6.1, tvOS 15.1, and watchOS 8.1.
- Prioritize patching internet-facing and high-value Apple devices first, given confirmed in-the-wild exploitation and KEV listing.
- Enforce a policy that only signed, vetted applications from trusted sources can be installed, reducing the chance of a malicious app reaching the vulnerable code path.
- Track device OS versions centrally and report on any endpoints still below the fixed releases.
Detection
- Monitor for unexpected kernel-level crashes or panics on Apple endpoints, which can accompany memory corruption exploitation.
- Alert on installation or execution of unsigned or sideloaded applications outside approved distribution channels.
- Correlate endpoint telemetry for processes gaining kernel privileges or unusual system-call behavior following app launches.
- Audit device inventory against the fixed OS versions to find unpatched assets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30883 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Apple Multiple Products Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT212846 | Vendor Advisory |
| https://support.apple.com/en-us/HT212868 | Vendor Advisory |
| https://support.apple.com/en-us/HT212869 | Vendor Advisory |
| https://support.apple.com/en-us/HT212872 | Vendor Advisory |
| https://support.apple.com/en-us/HT212874 | Vendor Advisory |
| https://support.apple.com/en-us/HT212876 | Vendor Advisory |
| https://support.apple.com/en-us/HT212846 | Vendor Advisory |
| https://support.apple.com/en-us/HT212868 | Vendor Advisory |
| https://support.apple.com/en-us/HT212869 | Vendor Advisory |
| https://support.apple.com/en-us/HT212872 | Vendor Advisory |
| https://support.apple.com/en-us/HT212874 | Vendor Advisory |
| https://support.apple.com/en-us/HT212876 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30883 | US Government Resource |
Track CVE-2021-30883 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30883), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.