An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A malicious application may be able to execute arbitrary code with kernel privileges.
Conclusion & alert: CVE-2021-30900 is rated Active Exploitation (78.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.48%).Core evidence: CISA KEV confirms active exploitation (added 2023-03-30) affecting Apple / iOS, iPadOS, and macOS. a weakness (CWE-787) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
CISA KEV Record for CVE-2021-30900
Name: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability · CISA KEV detail
Exploit added: 2023-03-30
Action due: 2023-04-20
Required action: Apply updates per vendor instructions.
Exploit prediction scoring system (EPSS) score for CVE-2021-30900
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).