First published: Mon Jul 19 2021(Updated: )
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6. A malicious application may be able to bypass certain Privacy preferences.
Credit: Mickey Jin @patch1t Trend Micro working with Trend Micro Zero Day InitiativeMickey Jin @patch1t Trend Micro working with Trend Micro Zero Day Initiative product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <7.6 | 7.6 |
Apple macOS Big Sur | <11.5 | 11.5 |
Apple iPhone OS | <14.7 | |
Apple macOS | <11.5 | |
Apple watchOS | <7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30798 is a logic issue in TCC (Transparency, Consent, and Control) that was addressed by Apple with improved state management.
CVE-2021-30798 affects Apple watchOS versions up to, but not including, 7.6.
CVE-2021-30798 affects Apple macOS Big Sur versions up to, but not including, 11.5.
To fix CVE-2021-30798 on Apple watchOS, update to version 7.6 or later.
To fix CVE-2021-30798 on Apple macOS Big Sur, update to version 11.5 or later.