Threat Intelligence / CVE / CVE-2021-30952

CVE-2021-30952

CISA KEV
CVSS 7.8 (HIGH) · EPSS 1.2% · Priority 9/10 · Published 2021-08-24

As of 2026-03-06, CVE-2021-30952 is a CVSS 7.8 (HIGH-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 1.2%. Threadlinqs Intelligence tracks 1 threat exploiting it.

Last updated: 2026-03-06

An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS v3 vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-190

Exploitation status

CISA KEV-listed (known exploited)

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2021-30952 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.