logo

CVE-2021-30737, @xerub's 2021 iOS ASN.1 Vulnerability

ID: ef823146-dca8-5812-ab0a-7e33069bc458

STIX ID: report--ef823146-dca8-5812-ab0a-7e33069bc458

Feed Name: Google Project Zero

Threat Score
85/100

Date Published: 2022-04-07

Date Updated: 2026-04-27

Author: Ryan

...
...

This report analyzes CVE-2021-30737, a serious memory‑corruption bug in Apple's ASN.1 decoder (Security.framework) stemming from an Apple-specific change to NSS made during an early fork. The author details how a crafted constructed bitstring can force the parser to NULL an output pointer, trigger an incorrect per-substring allocation, then overflow that allocation to produce an arbitrary memory‑corruption primitive enabling code execution; the writeup traces the defect to a 2003 import change and documents the patch that reverted the unsafe behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.