Cyber Resilience

CVE-2021-1870

Apple Mac Os X 10.15 – 10.15.7

CISA KEVActive ExploitationEUVD Exploited
Published
02 April 2021
Modified
23 October 2025
KEV Added
03 November 2021
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.079 94th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2021-1870 is a critical-severity an unspecified weakness vulnerability in Apple Mac Os X. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

A logic issue addressed with improved restrictions affects multiple Apple operating systems including macOS Big Sur prior to 11.2, macOS Catalina prior to Security Update 2021-001, macOS Mojave prior to Security Update 2021-001, and iOS/iPadOS prior to 14.4. The flaw carries a CVSS score of 9.8 and permits remote code execution without requiring authentication or user interaction.

A remote attacker can exploit the vulnerability over the network to achieve arbitrary code execution with full confidentiality, integrity, and availability impact on the target device. The attack vector requires no privileges or user interface interaction, making it suitable for unauthenticated remote exploitation.

Apple security updates for the listed macOS, iOS, and iPadOS versions resolve the issue. The vendor notes awareness of reports indicating the vulnerability may have been actively exploited in the wild.

EU & UK References

Vulnerability Data

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code…

more

execution. Apple is aware of a report that this issue may have been actively exploited..

CWE(s)
KEV Date Added
03 November 2021

Related Threats

CVEs Like This One

CVE-2021-1789Same product: Apple Ipadosboth on KEV
CVE-2021-1871Same product: Apple Ipadosboth on KEV
CVE-2023-42917Same product: Apple Ipadosboth on KEV
CVE-2023-42916Same product: Apple Ipadosboth on KEV
CVE-2022-32893Same product: Apple Ipadosboth on KEV
CVE-2021-30858Same product: Apple Ipadosboth on KEV
CVE-2021-30869Same product: Apple Ipadosboth on KEV
CVE-2021-30952Same product: Apple Ipadosboth on KEV
CVE-2022-2294Same product: Apple Ipadosboth on KEV
CVE-2023-32439Same product: Apple Ipadosboth on KEV

Affected Assets

apple
ipados
≤ 14.4
apple
iphone os
≤ 14.4
apple
mac os x
10.15.7 · 10.15 — 10.15.7
apple
macos
11.0.1 — 11.2
webkitgtk
webkitgtk
≤ 2.30.6
fedoraproject
fedora
32, 33

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References