CVE-2021-30955
Description
A race condition in Apple's kernel allows a malicious application to execute arbitrary code with kernel privileges; fixed in iOS 15.2, iPadOS 15.2, macOS Monterey 12.1, watchOS 8.3, and tvOS 15.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A race condition in Apple's kernel allows a malicious application to execute arbitrary code with kernel privileges; fixed in iOS 15.2, iPadOS 15.2, macOS Monterey 12.1, watchOS 8.3, and tvOS 15.2.
Vulnerability
A race condition exists in the kernel's state handling, which can be exploited by a malicious application to execute arbitrary code with kernel privileges. The vulnerability affects Apple's operating systems: iOS and iPadOS prior to 15.2, macOS Monterey prior to 12.1, watchOS prior to 8.3, and tvOS prior to 15.2 [1][2][3][4]. The issue was addressed with improved state handling.
Exploitation
An attacker must have the ability to run a malicious application on the target device. No additional privileges or user interaction beyond installing the app are required. The race condition is triggered during normal kernel operations, allowing the attacker to corrupt kernel memory and gain control.
Impact
Successful exploitation grants the attacker arbitrary code execution with kernel privileges, leading to full compromise of the device's operating system. This includes the ability to read and modify any data, install additional software, and bypass security mechanisms.
Mitigation
Apple released fixes on December 13, 2021, in iOS 15.2 and iPadOS 15.2 [1], macOS Monterey 12.1 [2], watchOS 8.3 [3], and tvOS 15.2 [4]. Users should update their devices to these versions immediately. No workarounds are available.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6<8.3+ 1 more
- (no CPE)range: <8.3
- (no CPE)range: unspecified
- Range: <12.1
- Range: <15.2
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
4- support.apple.com/en-us/HT212975mitrex_refsource_MISC
- support.apple.com/en-us/HT212976mitrex_refsource_MISC
- support.apple.com/en-us/HT212978mitrex_refsource_MISC
- support.apple.com/en-us/HT212980mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.