CVE-2021-30952Active Exploitation(apple / debian_linux)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch apple debian_linux systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

5.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • fedora
  • ipados
  • iphone_os

Threat summary

  • Active exploitation appears in 11 classified signals
  • Patch or workaround signal is available
  • 14 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 11 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • General: 1 classified signal
  • Peaked 6d ago at 6 mentions (2026-03-06); latest day: 1
  • 14 total mentions across 8 days

Affected systems

Products
debian_linuxfedoraipadosiphone_osmacossafaritvoswatchoswebkitgtkwpe_webkit

4 versions affected across 10 products

Deep dive

Activity timeline14 mentions / 8d
02356Mentions · 2026-03-05: 1Mentions · 2026-03-06: 6Mentions · 2026-03-09: 2Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-27: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-06: 4Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-27: 1Patch / Workaround · 2026-03-06: 3Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-27: 103-0503-0603-0903-1003-1103-1603-1703-27
Signal classification3 categories
Active Exploitation
1071.4%
Patch
321.4%
General
17.1%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-03-051
Active Exploitation1
2026-03-066
Active Exploitation3General1Patch2
2026-03-092
Active Exploitation1Patch1
2026-03-101
Active Exploitation1
2026-03-111
Active Exploitation1
2026-03-161
Active Exploitation1
2026-03-171
Active Exploitation1
2026-03-271
Active Exploitation1
Full discourse14 posts
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/5追加) 🛡️No.1533 CVE-2017-7921 Hikvision Multiple Products Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上で特権昇格を行う恐れがあります。また脆弱性の悪用により、機密情報にアクセスされる可能性があります。 https://www.hikvision.com/us-en/support/document-center/special-notices/privilege-escalating-vulnerability-in-certain-hikvision-ip-cameras/ 🛡️No.1534 CVE-2021-22681 Rockwell Multiple Products Insufficient Protected Credentials Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:認証情報の不十分な保護 (CWE-522 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、Studio 5000 Logix Designerソフトウェアにおいて、キーが発見される恐れがあります。このキーは、LogixコントローラがRockwell Automationの設計ソフトウェアと通信していることを確認するために使用されます。この脆弱性が悪用されると、不正なアプリケーションがLogixコントローラに接続できるようになる可能性があります。この脆弱性を悪用するには、不正なユーザーがコントローラへのネットワークアクセスが必要になります。 https://support.rockwellautomation.com/app/answers/answer_view/a_id/1130301/~/cve-2021-22681%3A-authentication-bypass-vulnerability-found-in-logix-controllers https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03 🛡️No.1535 CVE-2021-30952 Apple Multiple Products Integer Overflow or Wraparound Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:整数オーバーフローまたはラップアラウンド (CWE-190 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT212975 https://support.apple.com/en-us/HT212976 https://support.apple.com/en-us/HT212978 https://support.apple.com/en-us/HT212980 https://support.apple.com/en-us/HT212982 🛡️No.1536 CVE-2023-41974 Apple iOS and iPadOS Use-After-Free Vulnerability ============= CVSSスコア: 7.8 (Base) / CISA-ADP CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: アプリを介して、カーネル権限で任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT213938 https://support.apple.com/kb/HT213938 🛡️No.1537 CVE-2023-43000 Apple Multiple products Use-After-Free Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、メモリ破損が発生する恐れがあります。 https://support.apple.com/en-us/120324 https://support.apple.com/en-us/120331 https://support.apple.com/en-us/120338 CISA Adds Five Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA announced the addition of five known exploited vulnerabilities to its catalog, providing detailed technical information and vendor patch links, but without any proof‑of‑concept or exploit code.

    010203.5K
    42.6K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    🚨Cisco Catalyst SD-WANの脆弱性、さらに2件の悪用が明らかに:CVE-2026-20128、CVE-2026-20122 ⚠️米CISA、Apple製品の古い脆弱性3件をKEVカタログに追加(CVE-2023-43000、CVE-2021-30952、CVE-2023-41974) 〜サイバーアラート3月6日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44386/

    Post summary

    The post reports that two Cisco SD‑WAN vulnerabilities (CVE‑2026‑20128 and CVE‑2026‑20122) are being actively exploited, and also adds three older Apple product CVEs to the CISA KEV catalog.

    01010195
    1.2K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    The Coruna iOS exploit kit combines WebKit vulnerabilities with kernel exploits to achieve full device compromise. Attackers chain CVE-2023-41974 and CVE-2021-30952 for zero-click attacks via iMessage, then move laterally within devices to exfiltrate financial data and personal media. #MobileSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/coruna-ios-exploit-kit-2026-mass-attacks

    Post summary

    The Coruna iOS exploit kit actively exploits CVE-2023-41974 and CVE-2021-30952 in zero‑click iMessage attacks, then lags lateral movement to exfiltrate data.

    00001149
    1.9K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/03/05:Apple macOS/iOS などにおける複数の脆弱性を登録 https://iototsecnews.jp/2026/03/09/cisa-warns-of-macos-and-ios-vulnerabilities-exploited-in-attacks/ Apple の製品群で発見された深刻な脆弱性は、主にメモリ管理と計算処理の不備に起因するものです。具体的には、CVE-2023-43000/CVE-2023-41974 におけるメモリ解放後使用の問題と、CVE-2021-30952 における整数オーバーフローの問題です。メモリ解放後使用とは、プログラムが再割り当て済みのメモリを参照し続けることで不正なコード実行を許すものであり、整数オーバーフローは、数値計算の結果が記憶領域の上限を超えてしまうものです。これらの脆弱性を悪用する攻撃者は、悪意の Web コンテンツを介して、カーネル権限でのコード実行などを引きこす恐れがあります。確実な更新適用で保護できますので、早めの対応が推奨されます。 #Apple #CISA #CVE202130952 #CVE202341974 #CVE202343000 #Exploit #Government #iOS #KEV #macOS #Vulnerability

    Post summary

    The article announces that multiple critical Apple CVEs are being actively exploited in the wild, provides technical details and recommends applying updates for protection.

    01000143
    484 followersView on X
  • Grok@grok
    Active Exploitation

    Several Feb-Mar 2026 KEV additions include browser exploits: CVE-2026-2441 (Chromium CSS use-after-free, added Feb 17; hits Chrome/Edge/Opera via crafted HTML, active wild exploitation soon after). Also Apple Safari/web-content ones like CVE-2021-30952 (integer overflow) & CVE-2023-43000 (UAF), added Mar 5. No major defender surprises flagged beyond typical browser risks, but these prioritize patching. Check CISA catalog for full list (e.g., Mar 9 Ivanti/SolarWinds too).

    Post summary

    The post reports that CVE‑2026‑2441 is actively exploited in the web browser domain, highlights similar Safari vulnerabilities, and advocates patching, with reference to the CISA KEV catalog.

    0100044
    8.4M followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🚨 BREAKING: CISA adds FIVE new vulnerabilities to its Known Exploited Vulnerabilities Catalog! 🚨 🔍 CVE-2017-7921: Hikvision Improper Authentication 🔍 CVE-2021-22681: Rockwell Insufficient Protected Credentials 🔍 CVE-2021-30952: Apple Integer Overflow 🔍 CVE-2023-41974: Apple iOS/iPadOS Use-After-Free 🔍 CVE-2023-43000: Apple Use-After-Free ⚠️ These vulnerabilities are actively exploited and pose serious risks to federal systems. All organizations are urged to prioritize patching these vulnerabilities NOW to safeguard against cyber threats. Stay vigilant, stay protected! #NerdieNews #CyberSecurity #BreakingNews

    Post summary

    The post announces that five CVEs have been added to CISA's Known Exploited Vulnerabilities Catalog and stresses that they are actively exploited, urging immediate patching of federal systems.

    0000068
    49 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    CISAがCoruna関連のiOS 脆弱性 3件をKEV追加 iOS 13〜17.2.1を狙う23件の攻撃キット対応(CVE-2023-41974,CVE-2021-30952,CVE-2023-43000) https://rocket-boys.co.jp/security-measures-lab/cisa-adds-ios-coruna-flaws-to-kev-cve-2023-41974-2021-30952-2023-43000/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    CISA has added three iOS Coruna CVEs (CVE‑2023‑41974, CVE‑2021‑30952, CVE‑2023‑43000) to its KEV list, indicating they are being actively exploited by 23 attack kits against iOS 13‑17.2.1, with no mention of PoCs, patches, or debunking.

    00000104
    334 followersView on X
  • Nicolas Coolman@NicolasCoolman
    Active Exploitation

    CISA Alerte : Exploitation Active de CVE-2021-30952 dans les Produits Apple (tvOS, macOS, Safari, iPadOS, watchOS) https://zoneantimalware.com/apple-correctif-2/

    Post summary

    CISA alerts that CVE‑2021‑30952 is actively exploited across multiple Apple products, highlighting an urgent threat.

    0000041
    84 followersView on X
  • RagingCISO@CisoRaging77913
    Patch

    CVE-2021-30952, CVE-2023-41974, CVE-2023-43000: iOS exploits from 2021 still working in 2026. Coruna kit passed hands: US surveillance → state actors → Chinese criminals. Zero-day recycling market is real. Update your iPhones. Please.

    Post summary

    The post lists several iOS CVEs and warns that older exploits remain functional, urging users to update their devices.

    0000059
    5 followersView on X
  • xkzDB@xkzdb
    Patch

    🚨 CISA ordered U.S. federal agencies to patch three iOS security flaws targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit. <<<IMPORTANT>>> ⚡️ CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 added to CISA KEV catalog ⚡️ Coruna exploit kit uses 23 exploits across five chains targeting iOS 13–17.2.1 ⚡️ Deployed by threat actors for spyware, espionage, and stealing crypto wallets via PlasmaLoader ⚡️ Federal agencies must patch per BOD 22-01 Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    CISA has mandated federal agencies to patch three iOS CVEs that are actively exploited in espionage and crypto‑theft attacks through the Coruna exploit kit.

    0000096
    265 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção! A vulnerabilidade CVE-2021-30952 afeta produtos Apple (tvOS, macOS, Safari, iPadOS e watchOS) com risco de execução de código arbitrário devido a um overflow/integer wraparound. Aplique as mitig ações do fornecedor ou descontinue o uso. #CyberSecurity #InfoSec #CVE

    Post summary

    The post warns about CVE-2021-30952 in Apple products, indicating an overflow/integer wraparound vulnerability that allows arbitrary code execution, and advises applying vendor mitigations or discontinuing use.

    0000043
    255 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    General

    CVE-2021-30952 Apple 複数製品の整数オーバーフローまたはラップアラウンド脆弱性 CVE-2023-41974 Apple iOSおよびiPadOSのメモリ使用後の脆弱性 CVE-2023-43000 Apple 複数製品のメモリ解放後使用の脆弱性

    Post summary

    The text lists three Apple CVEs with short notes on the nature of each vulnerability but provides no further actionable details such as PoC, exploit code, or remediation steps.

    0000058
    47 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、5つの既知の脆弱性をカタログに追加 CISA Adds Five Known Exploited Vulnerabilities to Catalog #CISA (Mar 5) CVE-2017-7921 Hikvision 複数製品における不適切な認証の脆弱性 CVE-2021-22681 Rockwell 複数製品における保護された資格情報の不十分な脆弱性 CVE-2021-30952 Apple 複数製品の整数オーバーフローまたはラップアラウンド脆弱性 CVE-2023-41974 Apple iOSおよびiPadOSのメモリ使用後の脆弱性 CVE-2023-43000 Apple 複数製品のメモリ解放後使用の脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announces five CVEs that have been actively exploited in the wild, providing brief vulnerability type descriptions, but offers no PoC, exploit code, or patch information.

    00000256
    4.7K followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2021-30952 #Apple Multiple Products Integer Overflow or Wraparound Vulnerability https://www.scyscan.com/cve-2021-30952/apple-multiple-products-integer-overflow-or-wraparound-vulnerability/

    Post summary

    CVE-2021-30952, an Apple integer overflow vulnerability, is flagged as a known exploited vulnerability (#KEV), confirming it is actively being exploited in the wild, though no PoC, exploit, patch, or false positive claim is provided.

    0000048
    57 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSappletvos---
OSapplewatchos---
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSfedoraprojectfedora34--
OSfedoraprojectfedora35--
Appwebkitgtkwebkitgtk---
Appwpewebkitwpe_webkit---

Explore more