CVE-2021-1782 KEV
7.0
HIGH · CVSS 3.1 · EPSS 2.2% (pctl 82)
Patch first
On CISA KEV — known exploited in the wild, due 2021-11-17.
Description
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..
Scoring
| CVSS | 7.0 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.22% — more likely to be exploited than 82% of all CVEs |
| Weakness | CWE-667 |
| On CISA KEV | yes — remediate by 2021-11-17 |
| Public exploit | none known |
| Published | 2021-04-02 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apple Multiple Products Race Condition Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2021-11-17 |
| Vendor / product | Apple / Multiple Products |
| Ransomware use | none reported |
Affected (6)
| Vendor | Product |
|---|---|
| apple | ipados |
| apple | iphone os |
| apple | mac os x |
| apple | macos |
| apple | tvos |
| apple | watchos |
References
- https://support.apple.com/en-us/HT212146
- https://support.apple.com/en-us/HT212147
- https://support.apple.com/en-us/HT212148
- https://support.apple.com/en-us/HT212149
- https://support.apple.com/en-us/HT212146
- https://support.apple.com/en-us/HT212147
- https://support.apple.com/en-us/HT212148
- https://support.apple.com/en-us/HT212149
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1782
→ the Explorer · watch your stack · NVD