
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-30879 is an out-of-bounds read vulnerability discovered in Apple's AppleScript component. The vulnerability was fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, and macOS Big Sur 11.6.1, released on October 25, 2021. The vulnerability was discovered by security researcher Jeremy Brown along with researcher hjy79425575 (Apple Security Updates).
The vulnerability is classified as an out-of-bounds read issue (CWE-125) in the AppleScript component. The vulnerability received a CVSS v3.1 base score of 7.1 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H. The issue was addressed by implementing improved bounds checking in the affected systems (NVD).
When exploited, this vulnerability could allow processing of a maliciously crafted AppleScript binary to result in unexpected application termination or disclosure of process memory (Apple Security Updates).
Apple addressed this vulnerability by implementing improved bounds checking in the security updates released on October 25, 2021. Users should update to macOS Monterey 12.0.1, Security Update 2021-007 Catalina, or macOS Big Sur 11.6.1 to protect against this vulnerability (Apple Security Updates, Apple Catalina Update, Apple Big Sur Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."