ZeroHour

CVE-2021-1871

KEVmass

Actively Exploited WebKit Logic Flaw Enables Remote Code Execution on Apple iOS, iPadOS, and macOS

CISA: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2021-1871 is a logic flaw in Apple's WebKit browser engine that was addressed with improved restrictions, and it allows a remote attacker to achieve arbitrary code execution on affected Apple devices. The flaw is reachable over the network with no privileges required, and Apple disclosed in its advisory that it was aware of a report that the issue may have been actively exploited at the time of patching, making this a zero-day. Anyone running iOS or iPadOS versions prior to 14.4, macOS Big Sur prior to 11.2, or macOS Catalina/Mojave prior to Security Update 2021-001 is affected; Debian and Fedora also ship affected WebKit code in their distributions. The vulnerability carries a critical CVSS 3.1 score of 9.8, a 7.0% EPSS probability of exploitation within 30 days (94th percentile), and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with no public proof-of-concept known.

What to do: Update iPhones and iPads to iOS/iPadOS 14.4 or later, upgrade Macs to macOS Big Sur 11.2, and apply Security Update 2021-001 on Catalina and Mojave systems, as required under CISA's KEV directive. Debian and Fedora administrators should install the distribution-supplied WebKit/WebKitGTK security updates. Inventory for devices and web-content-processing systems that cannot be updated and consider restricting their exposure to untrusted web content until patched.

Affected
Apple iPhone OS (iOS)versions prior to iOS 14.4
Apple iPadOSversions prior to iPadOS 14.4
Apple macOS Big Surversions prior to macOS Big Sur 11.2
Apple macOS Catalinaversions prior to Security Update 2021-001 Catalina
Apple macOS Mojaveversions prior to Security Update 2021-001 Mojave
Debian Linux (WebKit/WebKitGTK packages)
Fedora Project Fedora (WebKit/WebKitGTK packages)
Estimated exposure
massbillions of Apple devices (iPhones, iPads, and Macs) on pre-patch iOS, iPadOS, or macOS versions at time of disclosure — Apple's install base spans over a billion active iPhones plus Macs and iPads, and public reporting on this fix described the bug as affecting billions of Apple devices; Debian/Fedora WebKit exposure is unquantified.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
appledebianfedoraproject
Products
ipados, iphone os, mac os x, macos, debian linux, fedora
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news