CVE detail
CVE-2021-30869
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of reports that an exploit for this issue exists in the wild.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.1 · diversity 9.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
14 source links · newest first
- China-linked APT group Salt Typhoon compromised some U.S. internet service providers (ISPs)Security Affairs
China-linked threat actors compromised some U.S. internet service providers (ISPs) as part of a cyber espionage campaign code-named Salt Typhoon. China-linked threat actors have breached several U.S. internet service providers in recent months as part of a cyber espionage campaign code-named Salt Typhoon. The state-sponsored hackers aimed at gathering intelligence from the targets or carrying […]
newssecurityaffairs.comSep 26, 2024, 2:04 PM - Chinese StormBamboo APT compromised ISP to deliver malwareSecurity Affairs
A China-linked APT, tracked as StormBamboo, compromised an internet service provider (ISP) to poison software update mechanisms with malware. Volexity researchers reported that a China-linked APT group, tracked as StormBamboo (aka Evasive Panda, Daggerfly, and StormCloud), successfully compromised an undisclosed internet service provider (ISP) in order to poison DNS responses for target organizations. The threat actors targeted […]
newssecurityaffairs.comAug 4, 2024, 3:55 PM - China-linked APT group uses new Macma macOS backdoor versionSecurity Affairs
China-linked APT group Daggerfly (aka Evasive Panda, Bronze Highland) Evasive Panda has been spotted using an updated version of the macOS backdoor Macma. The China-linked APT group Daggerfly (aka Evasive Panda or Bronze Highland) has significantly updated its malware arsenal, adding a new malware family based on the MgBot framework and an updated Macma macOS backdoor. […]
newssecurityaffairs.comJul 24, 2024, 10:09 AM - New DazzleSpy malware attacks macOSMalwarebytes Labs
DazzleSpy, a piece of malware that attacks macOS, was discovered last fall by researchers at ESET, and now those researchers have…
newswww.malwarebytes.comJan 25, 2022, 5:00 PM Experts found an undocumented macOS backdoor, dubbed DazzleSpy, that was employed in watering hole attacks aimed at politically active individuals in Hong Kong. Researchers from ESET have spotted an undocumented macOS backdoor, dubbed DazzleSpy, that was employed in watering hole attacks aimed at politically active individuals in Hong Kong. The investigation started in November after […]
newssecurityaffairs.comJan 25, 2022, 4:01 PMApple’s reputation on security has been taking a beating lately. As mentioned in some of our previous coverage, security researcher Joshua…
newswww.malwarebytes.comNov 15, 2021, 5:00 PMGoogle revealed that threat actors recently exploited a zero-day vulnerability in macOS to deliver malware to users in Hong Kong. Google TAG researchers discovered that threat actors leveraged a zero-day vulnerability in macOS in a watering hole campaign aimed at delivering malware to users in Hong Kong. The attackers exploited a XNU privilege escalation vulnerability […]
newssecurityaffairs.comNov 12, 2021, 3:57 PMGoogle on Thursday shared details about a recent attack that exploited a zero-day vulnerability in macOS to deliver malware to users in Hong Kong.
newswww.securityweek.comNov 12, 2021, 11:59 AMApple has released a security update for iOS and iPad that addresses a critical vulnerability reportedly being exploited in the wild.The…
newswww.malwarebytes.comOct 11, 2021, 5:00 PM- October 2021 Patch Tuesday forecast: Halloween came early this yearHelp Net Security
Halloween is not until the end of the month, but there has already been a lot of scary activity leading up to this patch Tuesday. PrintNightmare and Apple zero-days are just a few that have made the news. It’s been over three months since the vulnerabilities were announced, but PrintNightmare continues to be a scary topic of conversation. Microsoft changed the Point and Print feature functionality with their recent updates to require administrator privileges; however, … More →
newswww.helpnetsecurity.comOct 8, 2021, 5:57 AM - Week in review: How to retain best cybersecurity talent, securing Kubernetes, data decayHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and interviews: A new zero-day is being exploited to compromise Macs (CVE-2021-30869) Another zero-day in Apple’s software (CVE-2021-30869) is being actively exploited by attackers, forcing the company to push out security updates for macOS Catalina and iOS 12. Plug critical VMware vCenter Server flaw before ransomware gangs start exploiting it (CVE-2021-22005) VMware has fixed 19 vulnerabilities affecting VMware vCenter Server and VMware Cloud … More →
newswww.helpnetsecurity.comSep 26, 2021, 8:00 AM Another zero-day in Apple’s software (CVE-2021-30869) is being actively exploited by attackers, forcing the company to push out security updates for macOS Catalina and iOS 12. About CVE-2021-30869 Flagged by researchers Erye Hernandez and Clément Lecigne of Google’s Threat Analysis Group and Ian Beer of Google Project Zero, the vulnerability is a type confusion issue found in XNU, the kernel of Apple’s macOS and iOS operating systems. As usual, Apple did not share any details … More →
newswww.helpnetsecurity.comSep 24, 2021, 10:31 AMApple has addressed three zero-day vulnerabilities exploited by threat actors in attacks in the wild to take over iPhones and Macs. Apple has released security updates to address three zero-day vulnerabilities exploited in attacks in the wild to compromise iPhones and Macs running vulnerable iOS and macOS versions. Apple confirmed that at least one of […]
newssecurityaffairs.comSep 23, 2021, 8:49 PMApple on Thursday confirmed a new zero-day exploit hitting older iPhones and warned that the security vulnerability also affects the macOS Catalina platform.
newswww.securityweek.comSep 23, 2021, 8:39 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-30859CVSS 7.8 · High
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina. A malici…
- CVE-2021-1789CVSS 8.8 · High
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, t…
- CVE-2020-27932CVSS 7.8 · High
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 Hi…
- CVE-2026-43705CVSS 8.8 · High
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted w…
- CVE-2026-28983CVSS 7.5 · High
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.…
- CVE-2026-28822CVSS 6.2 · Medium
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, t…