CVE-2021-30761
KEVmassActively Exploited WebKit Memory Corruption in Apple iOS Enables Code Execution
CISA: Apple iOS WebKit Memory Corruption Vulnerability
CVE-2021-30761 is an out-of-bounds write (CWE-787), described by Apple as a memory corruption issue in WebKit that was addressed with improved state management. It is triggered when a user on an affected iPhone processes maliciously crafted web content, such as loading a hostile webpage, which may allow arbitrary code execution on the device. The flaw carries a CVSS 3.1 score of 8.8 (network attack vector, user interaction required, high impact on confidentiality, integrity, and availability). It affects devices running iOS versions prior to iOS 12.5.4, which in practice means older iPhones that remain on the iOS 12 branch, as reflected in press coverage about 'older iDevices'. Apple stated the issue may have been actively exploited in the wild; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, EPSS estimates a 10.5% probability of exploitation within 30 days (95th percentile), and no public PoC is known.
What to do: Update affected devices to iOS 12.5.4 or later per Apple's instructions, which is also the CISA KEV required action; prioritize older iPhones that only receive iOS 12 builds, given confirmed in-the-wild exploitation. Verify the installed iOS version in device settings and, until patched, limit loading untrusted web content on affected devices. Track the CISA KEV entry (added 2021-11-03) if you are subject to federal remediation timelines.
| Apple iOS (iPhone OS) | iOS versions prior to 12.5.4; fixed in iOS 12.5.4 (affects older iPhones limited to the iOS 12 branch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
- Affected
- Apple iOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- iphone os
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H