logo

CVE-2021-1782, an iOS in-the-wild vulnerability in vouchers

ID: a16202ee-4ffa-52ae-aa51-3d90640f2b5f

STIX ID: report--a16202ee-4ffa-52ae-aa51-3d90640f2b5f

Feed Name: Google Project Zero

Threat Score
80/100

Date Published: 2022-04-14

Date Updated: 2026-04-27

Author: Ryan

...
...

This Project Zero write-up dissects a race condition in the XNU 'voucher' subsystem (user_data attribute) that incorrectly increments a non-atomic counter (e_made), enabling a timing window where a user-controlled attribute element can be freed while still in use; the flaw can yield kernel memory read/write primitives and local privilege escalation. The analysis walks through voucher/data structures, locking, deduplication logic, the exact race windows, and includes a practical PoC that demonstrates triggering the bug; Apple patched the issue in iOS 14.4 and indicated potential active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.