ZeroHour

CVE-2021-30665

KEVmass

Memory Corruption in Apple WebKit Enables RCE on iOS, macOS, tvOS, watchOS

CISA: Apple Multiple Products WebKit Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
4%p89
Published
()
KEV added
AI analysis

CVE-2021-30665 is a memory corruption flaw (CWE-787, out-of-bounds write) in the WebKit engine shared across Apple's operating systems, fixed through improved state management. It is triggered when a device processes maliciously crafted web content, for example when a user loads an attacker-controlled web page or other web-rendered content, which is reflected in the required user-interaction element of the CVSS vector. Successful exploitation may lead to arbitrary code execution on the device. Essentially all Apple devices running versions of iOS, iPadOS, macOS Big Sur, tvOS, or watchOS earlier than the patched releases were affected, spanning the bulk of Apple's active installed base at the time. Apple reported the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; EPSS assigns a 3.7% probability of exploitation in the next 30 days (89th percentile).

What to do: Upgrade iPhones and iPads to iOS/iPadOS 14.5.1 (or iOS 12.5.3 on devices that cannot run 14.x), Macs to macOS Big Sur 11.3.1, Apple TVs to tvOS 14.6, and Apple Watches to watchOS 7.4.1. Because exploitation occurs through crafted web content, patching is the only reliable mitigation; use MDM or device inventory to confirm no managed Apple devices remain on pre-fix OS versions and treat any stragglers as actively at risk.

Affected
apple iOS (iPhone OS)all versions prior to 14.5.1; iOS 12.x prior to 12.5.3 (fixed in iOS 14.5.1 and iOS 12.5.3)
apple iPadOSall versions prior to 14.5.1 (fixed in iPadOS 14.5.1)
apple macOS (Big Sur)macOS Big Sur versions prior to 11.3.1 (fixed in Big Sur 11.3.1)
apple tvOSall versions prior to 14.6 (fixed in tvOS 14.6)
apple watchOSall versions prior to 7.4.1 (fixed in watchOS 7.4.1)
Estimated exposure
mass>1 billion active Apple devices (iOS/iPadOS/macOS/tvOS/watchOS installed base) — Apple publicly reported an installed base of roughly 1.65 billion active devices in early 2021, and WebKit is the common web-content engine across every listed product, so nearly all of those devices were exposed until the fixes shipped in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news