Security readout for executives and security teams
Plain-English summary
CVE-2021-30875 is an Apple lock screen privacy flaw. A person with local access to a locked iPhone or iPad may be able to view contacts without unlocking the device. Apple says the issue was fixed with improved state management in iOS 15.1 and iPadOS 15.1.
Executive priority
Prioritize remediation where devices handle sensitive contacts, executive directories, customer lists, or regulated personal data. This is not described as remote code execution, but it can create privacy and trust impact if a locked device is physically accessed.
Technical view
The public sources describe a lock screen state-management issue in iOS and iPadOS that could expose contacts from a locked device to a local attacker. Apple lists the fix in iOS 15.1 and iPadOS 15.1. No CVSS score, CWE, exact vulnerable build range, or technical root-cause detail is provided in the bundle.
Likely exposure
Exposure is most relevant to organizations with iPhones or iPads that were not updated to iOS 15.1 or iPadOS 15.1. The sources do not enumerate exact vulnerable versions, so asset validation should focus on OS versions and Apple advisory coverage.
Exploitation context
The cited description limits the attacker model to local access. The source bundle does not show CISA KEV listing, active exploitation, public exploit availability, or remote exploitation. Business risk is mainly privacy exposure from lost, unattended, shared, or physically accessed devices.
Researcher notes
Public evidence is sparse. Apple attributes the flaw to lock screen state management and says contacts may be viewable by a local attacker. The bundle provides no CVSS, CWE, affected version range, proof-of-concept status, or exploitation evidence beyond the vendor description.
Mitigation direction
- Update affected iPhone and iPad devices to iOS 15.1 or iPadOS 15.1 or later.
- Confirm managed device policies enforce current OS patch levels.
- Review Apple advisory HT212867 for vendor guidance and affected platform context.
- Treat lost, shared, or unattended devices as higher privacy risk until updated.
Validation and detection
- Inventory iOS and iPadOS device versions across managed and unmanaged fleets.
- Confirm devices meet or exceed iOS 15.1 or iPadOS 15.1.
- Check MDM compliance reports for stale, offline, or unmanaged devices.
- Verify incident records for lost or shared devices running older OS versions.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-30875 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://support.apple.com/en-us/HT212867CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
