ZeroHour

CVE-2021-30761

KEVmass

Actively Exploited WebKit Memory Corruption in Apple iOS Enables Code Execution

CISA: Apple iOS WebKit Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2021-30761 is an out-of-bounds write (CWE-787), described by Apple as a memory corruption issue in WebKit that was addressed with improved state management. It is triggered when a user on an affected iPhone processes maliciously crafted web content, such as loading a hostile webpage, which may allow arbitrary code execution on the device. The flaw carries a CVSS 3.1 score of 8.8 (network attack vector, user interaction required, high impact on confidentiality, integrity, and availability). It affects devices running iOS versions prior to iOS 12.5.4, which in practice means older iPhones that remain on the iOS 12 branch, as reflected in press coverage about 'older iDevices'. Apple stated the issue may have been actively exploited in the wild; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, EPSS estimates a 10.5% probability of exploitation within 30 days (95th percentile), and no public PoC is known.

What to do: Update affected devices to iOS 12.5.4 or later per Apple's instructions, which is also the CISA KEV required action; prioritize older iPhones that only receive iOS 12 builds, given confirmed in-the-wild exploitation. Verify the installed iOS version in device settings and, until patched, limit loading untrusted web content on affected devices. Track the CISA KEV entry (added 2021-11-03) if you are subject to federal remediation timelines.

Affected
Apple iOS (iPhone OS)iOS versions prior to 12.5.4; fixed in iOS 12.5.4 (affects older iPhones limited to the iOS 12 branch)
Estimated exposure
massplausibly tens of millions of legacy iPhones still on iOS 12, out of Apple's ~1-billion-device active iPhone installed base — Apple's active iPhone base is on the order of a billion devices, and because the only patch in this data was issued for the iOS 12 branch — with headlines describing 'older iDevices' — the practical exposure is the large cohort of legacy…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CISA Known Exploited Vulnerability
Affected
Apple iOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news