ZeroHour

CVE-2021-1789

KEVmass

Type Confusion RCE in Apple WebKit (iOS, macOS, Safari, tvOS, watchOS)

CISA: Apple Multiple Products Type Confusion Vulnerability

CVSS 3.1
8.8 high
EPSS
14%p96
Published
()
KEV added
AI analysis

CVE-2021-1789 is a type confusion flaw (CWE-843) in the WebKit engine that powers Safari and web views across Apple's platforms, fixed through improved state handling. An attacker triggers it by getting a victim to open or view maliciously crafted web content, for example via a crafted link in an email or a compromised webpage. Successful exploitation leads to arbitrary code execution in the context of the application rendering the content, and the CVSS 3.1 score of 8.8 reflects high confidentiality, integrity and availability impact with network attack vector and user interaction required. Everyone running affected Apple software below the February 2021 patch levels is exposed — iOS/iPadOS before 14.4, macOS Big Sur before 11.2, macOS Catalina/Mojave without Security Update 2021-001, tvOS before 14.4, watchOS before 7.3, and Safari before 14.0.3 — as well as WebKitGTK users on Fedora per the CPE data. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-05-04) and was used as a macOS zero-day in watering-hole attacks on Hong Kong pro-democracy users, deploying the DazzleSpy backdoor; EPSS estimates a 14.5% chance of exploitation in the next 30 days.

What to do: Update to iOS/iPadOS 14.4, macOS Big Sur 11.2 (or apply Security Update 2021-001 on Catalina/Mojave), Safari 14.0.3, tvOS 14.4 and watchOS 7.3; on Fedora, apply the available webkitgtk package update. Because this flaw is in CISA KEV and used in targeted watering-hole attacks, prioritize patching internet-facing and high-risk user fleets. Confirm inventory shows no Apple devices below these patch levels and that users are not relying on outdated Safari builds on unsupported macOS versions.

Affected
apple iOSprior to 14.4
apple iPadOSprior to 14.4
apple macOS Big Surprior to 11.2
apple macOS Catalinaprior to Security Update 2021-001
apple macOS Mojaveprior to Security Update 2021-001
apple tvOSprior to 14.4
apple watchOSprior to 7.3
apple Safariprior to 14.0.3
WebKitGTK
fedoraproject Fedora (webkitgtk package)
Estimated exposure
masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch) plus WebKitGTK-based Linux browsers/apps — Apple's active installed base exceeds a billion devices and every one running the affected iOS/macOS/Safari/tvOS/watchOS versions included a vulnerable WebKit, with Fedora/WebKitGTK adding a smaller but significant Linux user base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
applefedoraprojectwebkitgtk
Products
ipados, iphone os, mac os x, macos, tvos, watchos, fedora, webkitgtk
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news