LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30900: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 30, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 20, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30900 to its Known Exploited Vulnerabilities catalog on Mar 30, 2023, with a federal patch deadline of Apr 20, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges.

CVE-2021-30900 is an out-of-bounds write vulnerability in Apple GPU drivers that ship with iOS, iPadOS, and macOS. A malicious application can trigger the flaw and potentially execute code with kernel privileges, giving an attacker high-level control of the device. This matters for IT and security teams because kernel-level access can bypass many user-space controls, enable persistence, and support further compromise of managed Apple fleets.

Public detail is limited to the CISA summary and the stated CWE classes; confirm exact impact, affected builds, and exploitation status against the vendor advisory before acting.

How it works

The vulnerability combines improper input validation (CWE-20) with an out-of-bounds write (CWE-787) inside Apple GPU drivers. In this class of flaw, the driver fails to correctly bound-check data supplied by an application before writing it into memory. An attacker who can run a malicious application on the device can craft input that causes the driver to write outside the intended buffer. Because the GPU drivers operate with elevated privileges, a successful write can corrupt kernel memory structures and allow arbitrary code execution in the kernel context.

No public exploit mechanics beyond this high-level description are provided in the available facts. Defenders should treat any untrusted application that can reach the GPU interface as a potential trigger and should not assume user-space sandboxing alone is sufficient protection. Confirm the precise trigger conditions and any required privileges against the vendor advisory.

Am I affected? How to find it in your systems

The affected components are the GPU drivers included in Apple iOS, iPadOS, and macOS. These platforms are commonly found on corporate and personal iPhones, iPads, and Macs managed by MDM or endpoint tools. Inventory every Apple device in your environment—mobile, tablet, and desktop—and record the exact OS version and build currently installed.

If inventory data is incomplete, treat all unpatched Apple devices as potentially affected until confirmed otherwise.

How to remediate

The primary remediation is to apply the updates released by Apple according to the vendor instructions. CISA’s required action is simply to apply those updates. Once the vendor patch is installed, the out-of-bounds write condition in the GPU drivers is corrected.

Confirm the exact update names and build numbers against the vendor advisory; do not rely on third-party version lists.

If you can't patch immediately

When immediate patching is not possible, reduce the attack surface and increase detection until the vendor update can be applied.

These measures lower likelihood and impact but do not eliminate the vulnerability; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited kernel-privilege vulnerabilities can lead to full device compromise and subsequent data exposure. Known ransomware use of this specific CVE is not documented, yet any successful kernel-level code execution can still result in credential theft, lateral movement, or data exfiltration. If you suspect devices were compromised before patching, isolate them, collect forensic images, and rotate credentials that may have been present on the devices. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether any associated accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS, iPadOS, and macOS
WeaknessCWE-20
Added to CISA KEVMar 30, 2023
Federal patch deadlineApr 20, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities