Skip to main content

CVE detail

CVE-2021-30883

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVSS 7.8 · HighBuzz score 65.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 65.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 26.4 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
26.4
13 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
13 source links · newest first
  • Google’s Threat Analysis Group (TAG) has revealed a sophisticated spyware activity involving ISPs (internet service providers) aiding in downloading powerful commercial…

    newswww.malwarebytes.comJun 28, 2022, 5:00 PM
  • Google’s Threat Analysis Group (TAG) revealed that the Italian spyware vendor RCS Labs was supported by ISPs to spy on users. Researchers from Google’s Threat Analysis Group (TAG) revealed that the Italian surveillance firm RCS Labs was helped by some Internet service providers (ISPs) in Italy and Kazakhstan to infect Android and iOS users with […]

    newssecurityaffairs.comJun 24, 2022, 7:14 AM
  • Apple has released patches for iOS 15.3, iPadOS 15.3, and macOS Monterey 12.2 and is urging users to update. The most…

    newswww.malwarebytes.comJan 26, 2022, 5:00 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Apple fixes security feature bypass in macOS (CVE-2021-30892) Apple has delivered a barrage of security updates for most of its devices this week, and among the vulnerabilities fixed are CVE-2021-30892, a System Integrity Protection (SIP) bypass in macOS, and CVE-2021-30883, an iOS flaw that’s actively exploited by attackers. SolarWinds hackers are going after cloud, managed and IT service providers Nobelium, the … More →

    newswww.helpnetsecurity.comOct 31, 2021, 9:00 AM
  • Apple has delivered a barrage of security updates for most of its devices this week, and among the vulnerabilities fixed are CVE-2021-30892, a System Integrity Protection (SIP) bypass in macOS, and CVE-2021-30883, an iOS flaw that’s actively exploited by attackers. Source: Microsoft About CVE-2021-30883 CVE-2021-30883, a memory corruption issue in IOMobileFrameBuffer, was patched by the company in iOS and iPadOS v15.0.2 earlier this month, when Apple said that it was “aware of a report that … More →

    newswww.helpnetsecurity.comOct 29, 2021, 11:42 AM
  • Update now! Apple patches bugs in iOS and iPadOSMalwarebytes Labs

    On two consecutive days Apple has released a few important patches. iOS 14.8.1 comes just a month after releasing iOS 14.8…

    newswww.malwarebytes.comOct 26, 2021, 5:00 PM
  • 18th October – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 18th October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Israeli Medical Center Hillel Yaffe has been targeted by ransomware affecting the hospital’s computer systems, which have been working in a limited capacity since the attack occurred. Russia-based group TA505 is running […]

    vendorresearch.checkpoint.comOct 18, 2021, 3:53 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Help Net Security: XDR Report has been released The topic of this inaugural report is extended detection and response (XDR), an emerging technology that has been receiving a lot of buzz in the last few years. Apache OpenOffice users should upgrade to newest security release! The Apache Software Foundation (ASF) has released Apache OpenOffice 4.1.11, which fixes a handful of security … More →

    newswww.helpnetsecurity.comOct 17, 2021, 8:00 AM
  • Apple has silently addressed a zero-day vulnerability that could allow attackers to gain access to sensitive user data. Apple has silently addressed zero-day vulnerability with the release of iOS 15.0.2, the vulnerability could allow attackers gain access to sensitive user information. The flaw was reported to the IT giant by software developers Denis Tokarev seven […]

    newssecurityaffairs.comOct 13, 2021, 11:12 PM
  • With the newest iOS and iPad updates, Apple has fixed another vulnerability (CVE-2021-30883) that is being actively exploited by attackers. About CVE-2021-30883 CVE-2021-30883 is a memory corruption issue in IOMobileFrameBuffer, a kernel extension for managing the screen framebuffer. The vulnerability may be exploited by an application to execute arbitrary code with kernel privileges, Apple explained. As per usual, Apple did not share more details about the flaw or the attack(s) exploiting it, and the researcher … More →

    newswww.helpnetsecurity.comOct 12, 2021, 4:33 PM
  • Apple rushes out iOS 15.0.2 to address a remote code execution vulnerability that is being actively exploited Apple’s iOS zero-day problems appear to be getting worse.

    newswww.securityweek.comOct 12, 2021, 1:34 AM
  • Apple released emergency updates for both iOS and iPadOS to address a zero-day flaw that is actively exploited in the wild. Apple has released iOS 15.0.2 and iPadOS 15.0.2 to address a zero-day flaw, tracked as CVE-2021-30883, that is actively exploited in the wild. The flaw is a critical memory corruption issue that resides in […]

    newssecurityaffairs.comOct 11, 2021, 11:43 PM
  • Apple has released a security update for iOS and iPad that addresses a critical vulnerability reportedly being exploited in the wild.The…

    newswww.malwarebytes.comOct 11, 2021, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence