Original Release Date: 2/18/2021
Apple patched a vulnerability in macOS Big Sur versions 11.2 and 11.3 that could cause devices to get stuck in a boot loop and prevent users from accessing their data. The flaw exists because the installers do not verify available disk space; therefore, devices without the disk space to fully apply the update will be stuck in a boot loop. Some users were forced to erase and reinstall macOS, resulting in data loss. On February 15, 2021, Apple released a revised update – Big Sur 11.2.1 20D7 – which checks for disk space. While this issue is unlikely to be used by threat actors, it could compromise the availability of data, one of the principles of information security.
The NJCCIC recommends macOS users ensure they update their devices to the revised version, Big Sur 11.2.1 20D7. This flaw underscores the importance of testing updates prior to deployment, and the importance of home users, businesses, and organizations to implement a robust data backup plan to prevent data loss. More information can be found in the Mr. Macintosh post.