VYPR
Unrated severityNVD Advisory· Published Sep 8, 2021· Updated Aug 3, 2024

CVE-2021-30766

CVE-2021-30766

Description

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds write in the macOS kernel allows a malicious application to execute arbitrary code with kernel privileges.

Vulnerability

An out-of-bounds write vulnerability exists in the macOS kernel, specifically in the AMD kernel component. This issue affects macOS Big Sur before version 11.5, macOS Catalina before Security Update 2021-004, and macOS Mojave before Security Update 2021-005. The vulnerability was addressed by improving input validation to prevent memory corruption [1][2][3].

Exploitation

An attacker must have the ability to run a malicious application on the target system. No additional privileges beyond user-level access are required. The application can trigger the out-of-bounds write by sending crafted input to the kernel, leading to memory corruption. The exact exploitation steps are not publicly disclosed, but the vulnerability resides in the AMD kernel component [1][2][3].

Impact

Successful exploitation allows the application to execute arbitrary code with kernel privileges, resulting in full compromise of the system's confidentiality, integrity, and availability. The attacker gains the highest level of privilege, enabling complete control over the affected device [1][2][3].

Mitigation

Apple released fixes on July 21, 2021: macOS Big Sur 11.5, Security Update 2021-004 for Catalina, and Security Update 2021-005 for Mojave. Users should update to these patched versions. No workarounds are available. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog as of the publication date [1][2][3].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.