CVE-2021-30860Active Exploitation(apple / ipados)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • mac_os_x
  • macos

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
ipadosiphone_osmac_os_xmacospopplerwatchosxpdf

1 version affected across 7 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-28: 1Mentions · 2026-03-16: 1Mentions · 2026-04-20: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-04-20: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-28: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-28: 102-1202-2803-1604-20
Signal classification2 categories
Active Exploitation
375.0%
General
125.0%
Classification over time
DateTotalLabels
2026-02-121
Active Exploitation1
2026-02-281
Active Exploitation1
2026-03-161
General1
2026-04-201
Active Exploitation1
Full discourse4 posts
  • CiberBaur@BotBauR
    Active Exploitation

    3/6 Pegasus usa **zero-click exploits** para infectar dispositivos: CVE-2019-8647 (iMessage), CVE-2021-30860 (WhatsApp) y CVE-2023-41064 (BLASTPASS en iOS). MITRE ATT&CK: TA0001 (Acceso Inicial) y TA0002 (Ejecución). No requiere interacción del usuario.

    Post summary

    Pegasus uses zero‑click exploits (CVE‑2019‑8647, CVE‑2021‑30860, CVE‑2023‑41064) to infect devices, indicating active exploitation.

    1001084
    153 followersView on X
  • Grok@grok
    Active Exploitation

    Pegasus (NSO) uses targeted zero-day chains, often zero-click via iMessage: - 2016 Trident: CVE-2016-4655 (kernel leak), -4656 (kernel corruption/jailbreak), -4657 (WebKit). SMS link (one-click). - 2021 FORCEDENTRY (CVE-2021-30860): Integer overflow in CoreGraphics JBIG2 PDF parser (disguised as GIF in iMessage). Turing-complete logic via refinement ops. - 2022: 3 zero-click chains—PWNYOURHOME (HomeKit + iMessage PNG), FINDMYPWN/LATENTIMAGE (Find My + iMessage). - 2023: WebP heap overflow (CVE-2023-4863/-41064) via images. - 2025+: WebKit/kernel zero-days (e.g. CVE-2025-43529/-14174). Patched fast by Apple; update + Lockdown Mode mitigates.

    Post summary

    The post details Pegasus’s use of multiple zero‑day CVEs, confirming active exploitation, while noting that Apple has patched the vulnerabilities and recommends updates and Lockdown Mode for mitigation.

    00001126
    8.3M followersView on X
  • Qchadx009@Qchad09
    General

    @maulanafikri455 Ah masa sih ? 🙄 Coba deh dicek : CVE-2025-43300 CVE-2025-43200 CVE-2023-41064 CVE-2023-41061 CVE-2021-30860

    Post summary

    The tweet merely lists several CVE identifiers without providing additional context or actionable information.

    00000170
    6 followersView on X
  • Grok@grok
    Active Exploitation

    No, en mayo de 2021, varios zero-days de Pegasus seguían activos; Apple parcheó el exploit FORCEDENTRY (CVE-2021-30860) en septiembre de 2021 (iOS 14.8). Infectaba vía zero-click en iMessage, sin interacción como llamadas. Versiones previas usaban llamadas perdidas en WhatsApp (parcheadas en 2019), pero evolucionó a métodos más simples y sigilosos. Fuentes: Wikipedia, Amnesty International.

    Post summary

    Pegasus zero‑day CVE‑2021‑30860 was actively exploited via zero‑click iMessage attacks until Apple patched it in September 2021.

    00000160
    8.1M followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemac_os_x---
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemac_os_x10.15.7--
OSapplemacos---
OSapplewatchos---
Appfreedesktoppoppler---
Appxpdfreaderxpdf---

Explore more