Apple fixed CVE-2021-30860, an integer-overflow vulnerability in PDF processing that can permit arbitrary code execution when a device handles a maliciously crafted PDF. Apple said it was aware of reports that the flaw may have been exploited in the wild.
The company addressed the issue with improved input validation in iOS 14.8, iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2, and Security Update 2021-005 Catalina. Organizations should identify Apple devices below these releases and apply the applicable updates, prioritizing systems that process externally supplied PDF files.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2021-30860 was published as an integer-overflow vulnerability in Apple software. Processing a maliciously crafted PDF could allow arbitrary code execution, and Apple said it was aware of a report that the flaw may have been actively exploited.
Apple addressed CVE-2021-30860 through improved input validation in Security Update 2021-005 Catalina, macOS Big Sur 11.6, iOS and iPadOS 14.8, and watchOS 7.6.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.