CVE-2021-30955 is a race condition vulnerability in Apple operating systems (macOS Monterey, watchOS, iOS, iPadOS, tvOS) that could allow a malicious application to execute arbitrary code with kernel privileges. The vulnerability arises from improper state handling in the kernel, which could be exploited by an attacker to escalate privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is an iOS application ('Pentagram') designed to test if a device is vulnerable to CVE-2021-30955, a kernel race condition in IOKit. The app is written in Objective-C and C, and includes a GUI that allows the user to trigger the exploit via a button. The core exploit logic is implemented in 'desc_race.m' and 'spray_stuff.c', which perform memory spraying and race condition manipulation to achieve kernel code execution. The app checks the device's RAM size to determine which exploit variant to use, and provides user feedback via alerts. The exploit is a proof-of-concept and does not provide a full jailbreak, but demonstrates the ability to execute code in kernel context. The repository targets iOS 15.0-15.1.1 and 15.2 Beta 1 on devices with at least 4GB of RAM. No network endpoints are present; the attack vector is local, requiring the user to install and run the app on the target device.
This repository contains a proof-of-concept (POC) exploit for CVE-2021-30955, a kernel vulnerability in iOS 15.1. The exploit is implemented in C and consists of two main source files: 'desc_race.c' and 'spray_stuff.c', with corresponding headers. The exploit leverages a race condition in Mach message handling, combined with IOSurface object manipulation, to leak kernel memory and achieve arbitrary kernel memory writes. The code uses advanced techniques such as Mach port allocation, pipe spraying, and IOSurfaceRootUserClient interaction. The exploit is a POC and does not include a weaponized or fully automated payload, but demonstrates the core vulnerability and exploitation technique. No hardcoded IP addresses or network endpoints are present; the attack is local and targets the kernel via system APIs. The repository is well-structured, with clear separation between the race logic and the memory spraying/utilities.
This repository is a proof-of-concept (POC) exploit for CVE-2021-30955, targeting iOS 15.1.1 on A14 and A15 devices (e.g., iPhone 13 Pro Max). The exploit is implemented as an Xcode project using both Swift (for the UI and app logic) and C (for the exploit logic). The main exploit logic resides in 'desc_race_A15/exploit/desc_race.c' and 'spray_stuff.c', which perform a race condition attack on kernel message handling to achieve kernel memory write. The SwiftUI app provides a user interface to trigger the exploit on the device. Upon successful exploitation, the device achieves write privileges to kernel memory but immediately panics (crashes), and logs are generated in the system analytics data directory. The exploit does not provide a stable shell or persistent access and is intended for research and demonstration purposes only. The repository includes all necessary Xcode project files, Swift and C source code, and asset files for building and running the exploit app on a compatible iOS device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.