CVE-2021-30657mediumunder attackCWE-862

CVE-2021-30657: medium-severity vulnerability in Apple macOS

Published · Updated

92Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 5.5epss 69%
from disclosure to weapon60 days
Published on NVDSep 8
1st PoC+60d
metasploitMar 25
CISA KEV+56d
exploitation probability
69%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

A flaw in macOS allows a malicious app to bypass Gatekeeper, Apple's security check that prevents untrusted software from running. An attacker could trick your system into running harmful code that Gatekeeper should have blocked.

Technical detail

A logic vulnerability in macOS state management allows a malicious application to circumvent Gatekeeper's code-signing verification. The attack requires local execution context and improves attacker's capability to run unsigned or revoked code; Apple confirmed active exploitation in the wild.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
Apple · macOS
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.