A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A local user may be able to modify protected parts of the file system.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/houjingyi233/macOS-iOS-system-security