CVE-2021-1870
KEVmassWebKit Logic Flaw Enables Remote Code Execution on iOS, iPadOS, and macOS
CISA: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
CVE-2021-1870 is a logic flaw in Apple's WebKit browser engine, addressed in iOS 14.4, iPadOS 14.4, macOS Big Sur 11.2, and Security Update 2021-001 for Catalina and Mojave via improved restrictions. A remote attacker can trigger the flaw through hostile web content processed by WebKit on a vulnerable device, with no authentication or privileges required per the CVSS 3.1 network-vector scoring. Successful exploitation allows arbitrary code execution on the affected device. All users of iPhone OS/iPadOS prior to 14.4 and macOS prior to the listed fixes are affected, as WebKit ships with every Apple device, and WebKitGTK/Fedora users of the same engine are also potentially impacted. Apple reported the issue may have been actively exploited in the wild as a zero-day, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03.
What to do: Upgrade iPhones/iPads to iOS/iPadOS 14.4, Macs to macOS Big Sur 11.2, and apply Security Update 2021-001 on Catalina and Mojave. Fedora/WebKitGTK users should install the distribution's updated WebKitGTK packages. The issue is on the CISA KEV list with a required action of applying vendor updates; no public PoC or specific mitigation is known, so patching is the primary remediation.
| apple iphone os (iOS) | versions prior to iOS 14.4 |
| apple ipados | versions prior to iPadOS 14.4 |
| apple macos (Big Sur) | versions prior to macOS Big Sur 11.2 |
| apple mac os x (Catalina) | versions prior to Security Update 2021-001 Catalina |
| apple mac os x (Mojave) | versions prior to Security Update 2021-001 Mojave |
| webkitgtk | — |
| fedoraproject fedora | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple iOS, iPadOS, and macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- applewebkitgtkfedoraproject
- Products
- ipados, iphone os, mac os x, macos, webkitgtk, fedora
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H