CVE-2021-30663
KEVmass1WebKit Integer Overflow in Apple iOS, Safari, macOS and tvOS Allows Code Execution
CISA: Apple Multiple Products WebKit Integer Overflow Vulnerability
CVE-2021-30663 is an integer overflow (CWE-190) in Apple's WebKit browser engine that Apple addressed with improved input validation. It is triggered when a vulnerable device processes maliciously crafted web content, so simply visiting an attacker-controlled webpage is enough; the user-interaction requirement (UI:R) in the CVSS vector reflects this need to lure the victim. Successful exploitation allows arbitrary code execution with the privileges of the affected application, giving the attacker confidentiality, integrity, and availability impact on the device. All users of the affected Apple products—iOS/iPadOS, Safari on macOS, macOS Big Sur, and tvOS—are exposed, with the iOS 12.5.3 fix indicating older iPhones/iPads are also affected. Exploitation is confirmed in the wild: the flaw was patched in May 2021 amid reports of zero-day attacks, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown).
What to do: Update affected devices to the fixed releases: iOS 14.5.1 or iPadOS 14.5.1 (or iOS 12.5.3 on older devices that cannot run iOS 14), tvOS 14.6, Safari 14.1.1, and macOS Big Sur 11.3.1. As an interim mitigation, avoid visiting untrusted web content on unpatched devices. Because this flaw is on CISA's KEV list, federal agencies must apply the vendor updates per BOD 22-01 timelines, and defenders should inventory iOS, macOS, Safari, and tvOS versions to confirm no stragglers remain.
| Apple iOS | versions prior to iOS 14.5.1; also iOS versions prior to 12.5.3 on older devices |
| Apple iPadOS | versions prior to iPadOS 14.5.1 |
| Apple Safari | versions prior to Safari 14.1.1 |
| Apple macOS (Big Sur) | macOS Big Sur versions prior to 11.3.1 |
| Apple tvOS | versions prior to tvOS 14.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- safari, ipados, iphone os, macos, tvos
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H