LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30952: Apple Multiple Products Integer Overflow or Wraparound Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 5, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 26, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30952 to its Known Exploited Vulnerabilities catalog on Mar 5, 2026, with a federal patch deadline of Mar 26, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code…

Apple products including tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound weakness that can be triggered by malicious web content. Successful exploitation may allow arbitrary code execution on the affected system. The issue matters because these products are widely deployed in enterprise and personal environments where web browsing is routine, creating a pathway for remote compromise without user interaction beyond visiting a crafted page.

How it works

The weakness is classified as CWE-190, an integer overflow or wraparound. In this class of flaw an arithmetic operation on an integer value exceeds the maximum or minimum representable value for its type, producing an incorrect result that the program then uses in memory operations.

An attacker supplies specially crafted web content that causes the vulnerable integer calculation to wrap. The resulting incorrect value can be leveraged to corrupt memory structures, ultimately allowing the attacker to redirect execution flow to attacker-controlled code. No specific exploit mechanics beyond the processing of malicious web content are documented in the available summary.

Am I affected? How to find it in your systems

Inventory all Apple-managed endpoints and browsers in the environment, focusing on devices running tvOS, macOS, iPadOS, watchOS and any deployment of Safari. Use existing device management tools or asset inventories to list installed operating system and browser versions, then compare those versions against the ranges listed in the vendor advisory.

How to remediate

Apply the vendor-supplied update referenced in the official Apple security advisory as the primary remediation. After patching, review configurations that control web content handling and disable or restrict features that are not required for business operations.

If you can't patch immediately

Until patches can be deployed, reduce exposure by isolating systems that must process untrusted web content on separate network segments with strict egress controls. Consider virtual patching through web application firewalls or content-filtering proxies that can block or sanitize known malicious patterns associated with this vulnerability class.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to unauthorized access and data exposure in other incidents. Organizations can run a free exposure scan of corporate email addresses against known breach datasets to determine whether related credentials or data have already appeared in public repositories.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-190
Added to CISA KEVMar 5, 2026
Federal patch deadlineMar 26, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities