ZeroHour

CVE-2021-30663

KEVmass1

WebKit Integer Overflow in Apple iOS, Safari, macOS and tvOS Allows Code Execution

CISA: Apple Multiple Products WebKit Integer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
3%p89
Published
()
KEV added
AI analysis

CVE-2021-30663 is an integer overflow (CWE-190) in Apple's WebKit browser engine that Apple addressed with improved input validation. It is triggered when a vulnerable device processes maliciously crafted web content, so simply visiting an attacker-controlled webpage is enough; the user-interaction requirement (UI:R) in the CVSS vector reflects this need to lure the victim. Successful exploitation allows arbitrary code execution with the privileges of the affected application, giving the attacker confidentiality, integrity, and availability impact on the device. All users of the affected Apple products—iOS/iPadOS, Safari on macOS, macOS Big Sur, and tvOS—are exposed, with the iOS 12.5.3 fix indicating older iPhones/iPads are also affected. Exploitation is confirmed in the wild: the flaw was patched in May 2021 amid reports of zero-day attacks, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown).

What to do: Update affected devices to the fixed releases: iOS 14.5.1 or iPadOS 14.5.1 (or iOS 12.5.3 on older devices that cannot run iOS 14), tvOS 14.6, Safari 14.1.1, and macOS Big Sur 11.3.1. As an interim mitigation, avoid visiting untrusted web content on unpatched devices. Because this flaw is on CISA's KEV list, federal agencies must apply the vendor updates per BOD 22-01 timelines, and defenders should inventory iOS, macOS, Safari, and tvOS versions to confirm no stragglers remain.

Affected
Apple iOSversions prior to iOS 14.5.1; also iOS versions prior to 12.5.3 on older devices
Apple iPadOSversions prior to iPadOS 14.5.1
Apple Safariversions prior to Safari 14.1.1
Apple macOS (Big Sur)macOS Big Sur versions prior to 11.3.1
Apple tvOSversions prior to tvOS 14.6
Estimated exposure
masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV) and Safari users — Apple's iPhone/iPad installed base and macOS/Safari user base each run to hundreds of millions of devices, and WebKit is embedded across all of these platforms, so the potential affected population is far above the mass-scale threshold.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
safari, ipados, iphone os, macos, tvos
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news