Apple on Tuesday patched a zero-day vulnerability, CVE-2021-30657, that, if exploited, allows an attacker to bypass anti-malware checks. The flaw was discovered by Cedric Owens, a lead offensive security engineer with Twilio, who reported the bug to Apple. It has been used to install first-stage malware called Shlayer, which leads to advertising software being installed. Kaspersky estimated that in 2019, one in 10 users running its Mac security software encountered Shlayer.”]
Source: https://www.inforisktoday.com/apple-patches-worst-zero-day-bug-in-recent-memory-a-16463