← Back to browse · API

CVE-2021-1871

Severity
CRITICAL
CVSS
9.8
EPSS
0.0712
Risk score
66.69
CISA KEV
Yes
PoC
No
Published
2021-04-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-7335, GHSA-HVR3-8PVC-577J
Products
Apple:iOS and iPadOS unspecified <14.4, Apple:iOS, iPadOS, and macOS, Apple:macOS unspecified <11.2
Sources
cisa.gov CVE-2021-1871
euvd EUVD-2021-7335

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

References