CVE-2021-30665
KEVmassMemory Corruption in Apple WebKit Enables RCE on iOS, macOS, tvOS, watchOS
CISA: Apple Multiple Products WebKit Memory Corruption Vulnerability
CVE-2021-30665 is a memory corruption flaw (CWE-787, out-of-bounds write) in the WebKit engine shared across Apple's operating systems, fixed through improved state management. It is triggered when a device processes maliciously crafted web content, for example when a user loads an attacker-controlled web page or other web-rendered content, which is reflected in the required user-interaction element of the CVSS vector. Successful exploitation may lead to arbitrary code execution on the device. Essentially all Apple devices running versions of iOS, iPadOS, macOS Big Sur, tvOS, or watchOS earlier than the patched releases were affected, spanning the bulk of Apple's active installed base at the time. Apple reported the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; EPSS assigns a 3.7% probability of exploitation in the next 30 days (89th percentile).
What to do: Upgrade iPhones and iPads to iOS/iPadOS 14.5.1 (or iOS 12.5.3 on devices that cannot run 14.x), Macs to macOS Big Sur 11.3.1, Apple TVs to tvOS 14.6, and Apple Watches to watchOS 7.4.1. Because exploitation occurs through crafted web content, patching is the only reliable mitigation; use MDM or device inventory to confirm no managed Apple devices remain on pre-fix OS versions and treat any stragglers as actively at risk.
| apple iOS (iPhone OS) | all versions prior to 14.5.1; iOS 12.x prior to 12.5.3 (fixed in iOS 14.5.1 and iOS 12.5.3) |
| apple iPadOS | all versions prior to 14.5.1 (fixed in iPadOS 14.5.1) |
| apple macOS (Big Sur) | macOS Big Sur versions prior to 11.3.1 (fixed in Big Sur 11.3.1) |
| apple tvOS | all versions prior to 14.6 (fixed in tvOS 14.6) |
| apple watchOS | all versions prior to 7.4.1 (fixed in watchOS 7.4.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos, tvos, watchos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H