SecPod

Learn Search

Search across all Learn content

← Back to Security Research

Apple Patches Another High Severity Zero-Day Flaw (CVE-2021-30807) Exploited in the Wild

Apple Security Patches has released an urgent update to address a critical zero-day vulnerability that is being exploited in the wild. The vulnerability, tracked as CVE-2021-30807 and affects iOS, iPadOS, and macOS devices. This vulnerability exists due to a memory corruption issue in the IOMobileFr

Jul 27, 20212 min read

Apple Security Patches has released an urgent update to address a critical zero-day vulnerability that is being exploited in the wild. The vulnerability, tracked as CVE-2021-30807 and affects iOS, iPadOS, and macOS devices. This vulnerability exists due to a memory corruption issue in the IOMobileFrameBuffer component, a kernel extension for managing the screen frame buffer. It allows an attacker to execute arbitrary code with kernel privileges. Also, a vulnerability management tool can remediate this vulnerability.

Apple has released this update at a time when there are reports of a vulnerability in iMessage used by the Pegasus spyware for surveillance on dissidents, activists, human rights lawyers, and opposition politicians using Apple devices. Although the current Apple advisory does not mention this update includes a fix for the iMessage vulnerability also, few researchers believe in this possibility. A patch management solution can fix this vulnerability using a patch.

A long list of Zero-Days

CVE-2021-30807 adds to the long list of zero-days fixed by Apple this year. With most of them exploited in the wild, the list includes

Non patched endpoints are advised to deploy patches ASAP.

Affected Products

  • iOS before version 14.7.1
  • iPadOS before version 14.7.1
  • macOS Big Sur before version 11.5.1

Impact

A memory corruption issue allows attackers to execute arbitrary code on the affected system.

Solution

  • iOS 14.7.1
  • iPadOS 14.7.1
  • macOS Big Sur 11.5.1

SanerNowdetects these vulnerabilities and automatically fixes them through patch management by applying security updates. We strongly recommend applying the security updates as soon as possible following the instructions published in our support article.

Featured Posts

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026

Open Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files
Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

CVE Research

Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

Fortinet has disclosed CVE-2026-104286, a critical unauthenticated path traversal and NULL-byte handling vulnerability in FortiMail that allows arbitrary file writes via crafted HTTP or HTTPS requests. The issue is reported as exploited in the wild and is listed in the CISA KEV catalog. This article covers impact, affected versions, workarounds, fixed-build guidance, and indicators of compromise.

Oct 5, 2026

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026