CVE-2021-30937
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 18%
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to execute arbitrary code with kernel privileges.
References
http://packetstormsecurity.com/files/165475/XNU-inm_merge-Heap-Use-After-Free.htmlhttps://support.apple.com/en-us/HT212975https://support.apple.com/en-us/HT212976https://support.apple.com/en-us/HT212978https://support.apple.com/en-us/HT212979https://support.apple.com/en-us/HT212980https://support.apple.com/en-us/HT212981