Vulnerabilities > CVE-2021-30925 - Incorrect Authorization vulnerability in Apple products

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
apple
CWE-863
critical

Summary

The issue was addressed with improved permissions logic. This issue is fixed in watchOS 8, macOS Big Sur 11.6, iOS 15 and iPadOS 15. A malicious application may be able to bypass Privacy preferences.

Vulnerable Configurations

Part Description Count
OS
Apple
354

Common Weakness Enumeration (CWE)