CVE-2021-30666
KEVmassWebKit Buffer Overflow in Apple iOS Allows Code Execution via Malicious Web Content
CISA: Apple iOS WebKit Buffer Overflow Vulnerability
CVE-2021-30666 is a buffer overflow (CWE-119) in the WebKit web engine on Apple iOS, caused by improper memory handling. It is triggered remotely when the device processes maliciously crafted web content, meaning a victim only has to encounter attacker-controlled web pages or web content for the flaw to be reached (network vector with user interaction, per the CVSS 3.1 score of 8.8). Successful exploitation can lead to arbitrary code execution on the device with full confidentiality, integrity, and availability impact. All iOS devices running versions before the iOS 12.5.3 fix are affected, with iOS 12.5.3 serving devices that remain on Apple's legacy iOS 12 branch. Apple reported the bug was being actively exploited in the wild when it was patched, CISA added it to the KEV on 2021-11-03, and EPSS assigns a 3% probability of exploitation within 30 days (87th percentile), though no public PoC is known.
What to do: Upgrade affected devices to iOS 12.5.3 or later, and have devices on newer iOS branches take the corresponding current-branch iOS security updates Apple released at the same time, per CISA's required action to apply updates per vendor instructions. Because the attack vector is web content and no public workaround is documented, patching WebKit is the primary defense, so prioritize older hardware that only receives iOS 12.5.x updates and verify fleet-wide compliance.
| Apple iPhone OS (iOS) | All versions prior to iOS 12.5.3 (fix released in the iOS 12.5.x legacy-branch update; source data specifies no other version ranges) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple iOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- iphone os
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H