← Back to browse · API

CVE-2021-1870

Severity
CRITICAL
CVSS
9.8
EPSS
0.07921
Risk score
66.97
CISA KEV
Yes
PoC
No
Published
2021-04-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-7334, GHSA-F8FH-G8MV-P7HH
Products
Apple:iOS and iPadOS unspecified <14.4, Apple:iOS, iPadOS, and macOS, Apple:macOS unspecified <11.2
Sources
cisa.gov CVE-2021-1870
euvd EUVD-2021-7334

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

References