NVD disclosure day

Published threat advisories for August 24, 2021

CVE advisoryKnown Exploit

CVE-2021-30983

Apple iOS and iPadOS Kernel Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A buffer overflow in Apple operating systems allows an application to execute arbitrary code with kernel privileges, posing a risk of unauthorized system control and data compromise. This vulnerability impacts affected devices and requires prompt attention.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-30952

Apple Software Vulnerability May Allow Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Certain Apple software, including Safari and macOS, is affected by an integer overflow vulnerability. This flaw could allow an attacker to execute arbitrary code on affected systems by processing maliciously crafted web content. The business risk includes potential data compromise and unauthorized system access.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-30900

Apple Operating System Out-of-Bounds Write Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An out-of-bounds write in Apple operating systems allows malicious applications to gain kernel privileges. This poses a risk to affected organizations by potentially compromising devices and data. Updates are available to address this issue.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-30883

Apple Operating Systems Memory Corruption Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability in Apple operating systems could allow an application to execute arbitrary code with kernel privileges. Apple is aware of reports indicating this issue may have been exploited, posing a risk to affected devices and data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-30860

Apple PDF Vulnerability Allows Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in certain Apple software that could allow unauthorized code execution when processing a malicious PDF. This poses a business risk to affected organizations by potentially compromising systems and data, especially as active exploitation has been reported. Mitigation involves applying vendor-provi

• CISA KEV