CVE-2021-30937
Description
A memory corruption issue in Apple's kernel (XNU) allows a malicious app to execute arbitrary code with kernel privileges, fixed in iOS 15.2, macOS Monterey 12.1, and others.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory corruption issue in Apple's kernel (XNU) allows a malicious app to execute arbitrary code with kernel privileges, fixed in iOS 15.2, macOS Monterey 12.1, and others.
Vulnerability
A memory corruption vulnerability exists in the XNU kernel of Apple operating systems. The flaw was addressed with improved locking mechanisms. Affected versions include macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, and watchOS 8.3 [1][2][3][4].
Exploitation
An attacker would need to have the ability to run a malicious application on the target device. No additional privileges or user interaction beyond launching the app are required. The exploitation involves triggering a race condition or improper locking that leads to memory corruption.
Impact
Successful exploitation allows the malicious application to execute arbitrary code with kernel privileges, resulting in full compromise of the operating system's security. This could lead to unauthorized data access, modification, or persistent control over the device [1].
Mitigation
Apple released fixes in iOS 15.2, iPadOS 15.2, macOS Monterey 12.1, macOS Big Sur 11.6.2, Security Update 2021-008 Catalina, tvOS 15.2, and watchOS 8.3 on December 13, 2021. Users should update to these versions or later. No workarounds are available beyond applying the security update [1][2][3][4].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
10- Range: <11.6.2
- Range: <2021-008
- Range: <15.2
- Range: <15.2
<8.3+ 1 more
- (no CPE)range: <8.3
- (no CPE)range: unspecified
- Range: <12.1
- Range: <15.2
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
7- packetstormsecurity.com/files/165475/XNU-inm_merge-Heap-Use-After-Free.htmlmitrex_refsource_MISC
- support.apple.com/en-us/HT212975mitrex_refsource_MISC
- support.apple.com/en-us/HT212976mitrex_refsource_MISC
- support.apple.com/en-us/HT212978mitrex_refsource_MISC
- support.apple.com/en-us/HT212979mitrex_refsource_MISC
- support.apple.com/en-us/HT212980mitrex_refsource_MISC
- support.apple.com/en-us/HT212981mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.