CVE-2021-1871
KEVmassActively Exploited WebKit Logic Flaw Enables Remote Code Execution on Apple iOS, iPadOS, and macOS
CISA: Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
CVE-2021-1871 is a logic flaw in Apple's WebKit browser engine that was addressed with improved restrictions, and it allows a remote attacker to achieve arbitrary code execution on affected Apple devices. The flaw is reachable over the network with no privileges required, and Apple disclosed in its advisory that it was aware of a report that the issue may have been actively exploited at the time of patching, making this a zero-day. Anyone running iOS or iPadOS versions prior to 14.4, macOS Big Sur prior to 11.2, or macOS Catalina/Mojave prior to Security Update 2021-001 is affected; Debian and Fedora also ship affected WebKit code in their distributions. The vulnerability carries a critical CVSS 3.1 score of 9.8, a 7.0% EPSS probability of exploitation within 30 days (94th percentile), and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with no public proof-of-concept known.
What to do: Update iPhones and iPads to iOS/iPadOS 14.4 or later, upgrade Macs to macOS Big Sur 11.2, and apply Security Update 2021-001 on Catalina and Mojave systems, as required under CISA's KEV directive. Debian and Fedora administrators should install the distribution-supplied WebKit/WebKitGTK security updates. Inventory for devices and web-content-processing systems that cannot be updated and consider restricting their exposure to untrusted web content until patched.
| Apple iPhone OS (iOS) | versions prior to iOS 14.4 |
| Apple iPadOS | versions prior to iPadOS 14.4 |
| Apple macOS Big Sur | versions prior to macOS Big Sur 11.2 |
| Apple macOS Catalina | versions prior to Security Update 2021-001 Catalina |
| Apple macOS Mojave | versions prior to Security Update 2021-001 Mojave |
| Debian Linux (WebKit/WebKitGTK packages) | — |
| Fedora Project Fedora (WebKit/WebKitGTK packages) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple iOS, iPadOS, and macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- appledebianfedoraproject
- Products
- ipados, iphone os, mac os x, macos, debian linux, fedora
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H