CVE-2021-1782KEV · OVERDUE

Apple Multiple Products Race Condition Vulnerability

High · published April 2, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.0. It is confirmed in active exploitation. It sits in the 81.5th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.0
EPSS
2%
Percentile
81.5
In the wild
Confirmed
What it is

🚨 A sneaky race condition just got a fix! This vulnerability in Apple’s systems could let a malicious app elevate its privileges—yikes! ⚡ Think of this like a busy restaurant kitchen where two chefs accidentally reach for the last ingredient at the same time—if one chef gets it first, they might serve a totally different dish! In our case, it means an attacker could grab control when they shouldn’t. An attacker could exploit this race condition to run unauthorized commands, gaining access to sensitive data or performing actions they’re not allowed to. This could lead to data breaches, system instability, or worse—compromised devices all over the place!

Put simply

Think of this like a busy restaurant kitchen where two chefs accidentally reach for the last ingredient at the same time—if one chef gets it first, they might serve a totally different dish! In our case, it means an attacker could grab control when they shouldn’t. This vulnerability arises from improper locking mechanisms, allowing multiple processes to access critical resources simultaneously. When exploited, it opens the door for privilege escalation, letting malicious apps run amok on your system.

What to do

An attacker could exploit this race condition to run unauthorized commands, gaining access to sensitive data or performing actions they’re not allowed to. This could lead to data breaches, system instability, or worse—compromised devices all over the place! To safeguard your devices, update to macOS Big Sur 11.2, or apply Security Update 2021-001 for Catalina and Mojave. Ensure all iOS and iPadOS devices are upgraded to version 14.4 as well. Don't wait—protect your precious data! You can do this! Update your systems and keep those attackers at bay! 🛡️

The record
Technical detail
CVSS v3.1
7.0 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.02222 · 81.5th percentile
Published
2021-04-02T17:59Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 02 APR 17:59Z
    A race condition was addressed with improved locking
    cvelistv5