VYPR
Unrated severityNVD Advisory· Published Sep 8, 2021· Updated Aug 3, 2024

CVE-2021-30765

CVE-2021-30765

Description

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds write in macOS kernel (AMD driver) allows a local application to execute arbitrary code with kernel privileges, patched in July 2021 updates.

Vulnerability

An out-of-bounds write vulnerability exists in the AMD kernel component of macOS. The issue is a memory corruption bug that was addressed with improved input validation. Affected versions include macOS Big Sur before 11.5, macOS Catalina before Security Update 2021-004, and macOS Mojave before Security Update 2021-005. The bug is reachable by a local application that can trigger the vulnerable code path through a crafted request to the AMD kernel driver [1][2][3].

Exploitation

An attacker needs local access to the system and the ability to execute a malicious application. No additional privileges are required initially; the application interacts with the kernel-level AMD driver to trigger the out-of-bounds write. The specific exploit sequence involves sending malformed input to the driver that bypasses insufficient validation, causing a write past the allocated buffer boundary [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code with kernel privileges. This gives full control over the operating system, enabling the attacker to bypass security mechanisms, access sensitive data, install persistent malware, or perform any action the kernel can execute [1][2][3].

Mitigation

Apple released fixed versions on July 21, 2021: macOS Big Sur 11.5, Security Update 2021-004 for Catalina, and Security Update 2021-005 for Mojave. Users should apply these updates via Software Update. No workaround exists, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing [1][2][3].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.