Apple released macOS Big Sur 11.2 and Security Update 2021-001 for Catalina and Mojave to address numerous vulnerabilities affecting the kernel, WebKit, ImageIO, CoreText, CoreGraphics, CFNetwork, NetFSFramework, XNU, and other components. The flaws could enable denial of service, information disclosure, arbitrary code execution, and kernel-level compromise.
Among the fixes, CVE-2021-1782 is a race-condition flaw that allowed a malicious application to elevate privileges; Apple said it may have been actively exploited and corrected it through improved locking. Apple also reported potential in-the-wild exploitation of CVE-2021-1764 in the Kernel and CVE-2021-1789 in WebKit, underscoring the need to apply the available macOS security updates.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2021-1782 was published, identifying a race-condition privilege-escalation flaw that Apple said may have been actively exploited. Apple had addressed it with improved locking in iOS, iPadOS, macOS, watchOS, and tvOS updates.
Apple released security updates for macOS Big Sur, Catalina, and Mojave, addressing numerous vulnerabilities across components including the kernel and WebKit. Apple said CVE-2021-1764 (Kernel) and CVE-2021-1789 (WebKit) may have been actively exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.