LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30860: Apple Multiple Products Integer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30860 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known…

CVE-2021-30860 is an integer overflow vulnerability in the CoreGraphics component used across Apple iOS, iPadOS, macOS, and watchOS. Processing a maliciously crafted PDF can lead to code execution. It is also known as FORCEDENTRY. For defenders, this matters because PDF handling is common on endpoints and mobile devices; a successful exploit can give an attacker a foothold without the user deliberately running untrusted software. Confirm exact product scope and fixed builds against the vendor advisory.

CISA lists the required action as applying updates per vendor instructions. Ransomware use is not documented for this CVE in the provided facts.

How it works

The weakness is classified under CWE-190 (integer overflow) and CWE-20 (improper input validation). In CoreGraphics, integer arithmetic used while parsing or rendering PDF content can overflow. When bounds or size calculations wrap incorrectly, memory corruption can follow, which may allow arbitrary code execution in the context of the process that opens the PDF.

An attacker abuses this by delivering a specially crafted PDF—via message, email, web download, or another channel that causes the device to process the file with CoreGraphics. The defender should treat any untrusted PDF as a potential trigger until systems are patched. Specific exploit mechanics, payloads, or reliability details are not provided here; rely on the vendor advisory and your own threat intelligence for operational detail.

Am I affected? How to find it in your systems

This affects Apple platforms that include CoreGraphics for PDF handling: iOS, iPadOS, macOS, and watchOS. Typical locations include employee iPhones and iPads, Mac laptops and desktops (including those used for document review), and Apple Watch devices managed by the organization.

How to remediate

Patch first. Apply the updates Apple released for the affected products, following the vendor instructions referenced by CISA. Use MDM or organizational update channels to drive iOS, iPadOS, macOS, and watchOS to the fixed builds as quickly as testing allows.

If you can't patch immediately

Until updates are installed, reduce likelihood and impact with compensating controls.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and follow-on data theft. If you suspect exposure, isolate affected devices, rotate credentials accessible from them, and begin incident response per your playbooks. You can run a free exposure scan of your email addresses against known breach data to see whether those identities already appear in public breach corpora, then prioritize monitoring and password resets accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities