ZeroHour

CVE-2021-1870

KEVmass

WebKit Logic Flaw Enables Remote Code Execution on iOS, iPadOS, and macOS

CISA: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2021-1870 is a logic flaw in Apple's WebKit browser engine, addressed in iOS 14.4, iPadOS 14.4, macOS Big Sur 11.2, and Security Update 2021-001 for Catalina and Mojave via improved restrictions. A remote attacker can trigger the flaw through hostile web content processed by WebKit on a vulnerable device, with no authentication or privileges required per the CVSS 3.1 network-vector scoring. Successful exploitation allows arbitrary code execution on the affected device. All users of iPhone OS/iPadOS prior to 14.4 and macOS prior to the listed fixes are affected, as WebKit ships with every Apple device, and WebKitGTK/Fedora users of the same engine are also potentially impacted. Apple reported the issue may have been actively exploited in the wild as a zero-day, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03.

What to do: Upgrade iPhones/iPads to iOS/iPadOS 14.4, Macs to macOS Big Sur 11.2, and apply Security Update 2021-001 on Catalina and Mojave. Fedora/WebKitGTK users should install the distribution's updated WebKitGTK packages. The issue is on the CISA KEV list with a required action of applying vendor updates; no public PoC or specific mitigation is known, so patching is the primary remediation.

Affected
apple iphone os (iOS)versions prior to iOS 14.4
apple ipadosversions prior to iPadOS 14.4
apple macos (Big Sur)versions prior to macOS Big Sur 11.2
apple mac os x (Catalina)versions prior to Security Update 2021-001 Catalina
apple mac os x (Mojave)versions prior to Security Update 2021-001 Mojave
webkitgtk
fedoraproject fedora
Estimated exposure
masson the order of 1+ billion Apple devices (WebKit ships in every iPhone, iPad, and Mac) — WebKit is the built-in browser engine on all iOS, iPadOS, and macOS devices, so Apple's global active-device install base (reported in the billions by coverage of this patch) bounds the exposed population; WebKitGTK/Fedora exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
applewebkitgtkfedoraproject
Products
ipados, iphone os, mac os x, macos, webkitgtk, fedora
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news