CVE-2021-30657

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 20, 2026 9 articles

EPSS Score

Source: FIRST.org · 2026-05-24
83.08%
probability
This CVE has a 83.08% probability of being exploited in the next 30 days.
0% Top 99.3th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

shubham0d/CVE-2021-30657

A sample POC for CVE-2021-30657 affecting MacOS

30
1 repo — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 83.08%
Mentions 9
Last Seen Nov 09, 2021

CNA Information

Analyst Note

Multiple authoritative sources (BleepingComputer) explicitly state CVE-2021-30657 was a zero-day exploited in the wild, fixed by Apple in iOS 15.0.2. Article titles confirm active exploitation preceded or coincided with patch availability (e.g., 'Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks'). The 2021 CVE year aligns with the 2021 patch date, and multiple independent reports confirm exploitation by NSO spyware actors.

Threat Actors 1

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP

Triage Info

Decided atMar 20, 2026