First published: Tue Aug 24 2021(Updated: )
A race condition was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to elevate privileges.
Credit: Mickey Jin @patch1t Trend MicroMickey Jin @patch1t Mickey Jin @patch1t Trend MicroMickey Jin @patch1t Mickey Jin @patch1t Trend MicroMickey Jin @patch1t Mickey Jin @patch1t Trend MicroMickey Jin @patch1t Mickey Jin @patch1t Trend MicroMickey Jin @patch1t Mickey Jin @patch1t Trend MicroMickey Jin @patch1t cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <15.2 | |
Apple iPhone OS | <15.2 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-security_update_2020-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-001 | |
Apple Mac OS X | =10.15.7-security_update_2021-002 | |
Apple Mac OS X | =10.15.7-security_update_2021-003 | |
Apple Mac OS X | =10.15.7-security_update_2021-004 | |
Apple Mac OS X | =10.15.7-security_update_2021-005 | |
Apple Mac OS X | =10.15.7-security_update_2021-006 | |
Apple Mac OS X | =10.15.7-security_update_2021-007 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.6.2 | |
Apple macOS | >=12.0<12.1 | |
Apple tvOS | <15.2 | |
Apple watchOS | <8.3 | |
Apple tvOS | <15.2 | 15.2 |
Apple watchOS | <8.3 | 8.3 |
Apple iOS | <15.2 | 15.2 |
Apple iPadOS | <15.2 | 15.2 |
Apple macOS Monterey | <12.1 | 12.1 |
Apple Catalina | ||
Apple macOS Big Sur | <11.6.2 | 11.6.2 |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2021-30995.
The title of the vulnerability is 'Preferences. A race condition was addressed with improved state handling.'
The vulnerability involves a race condition in the Preferences feature and has been addressed with improved state handling.
The following software products are affected: Apple Catalina, macOS Monterey (up to version 12.1), macOS Big Sur (up to version 11.6.2), watchOS (up to version 8.3), iOS (up to version 15.2), iPadOS (up to version 15.2), and tvOS (up to version 15.2).
To fix this vulnerability, you should update the affected software to the latest version provided by Apple.
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-362.
You can find more information about this vulnerability on the Apple support website. Here are some references: [Link 1](https://support.apple.com/en-us/HT212980), [Link 2](https://support.apple.com/en-us/HT212978), [Link 3](https://support.apple.com/en-us/HT212975).