Zero-day vulnerability in macOS

Input validation error

Known malware:


Vulnerability details

Advisory: SB2021052415 - Multiple vulnerabilities in Apple macOS Big Sur

Vulnerable component: macOS

CVE-ID: CVE-2021-30713

CVSSv3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C

CWE-ID: CWE-20 - Improper input validation


The vulnerability allows a local user to bypass Privacy preferences.

The vulnerability exists due to insufficient validation of user-supplied input within the TCC subsystem. A malicious application can  bypass Privacy preferences and gain full disk access, perform screen recording or gain other permissions without requiring user's explicit consent.

Note, the vulnerability is being actively exploited in the wild by XCSSET malware.

External links: