ZeroHour

CVE-2021-30858

KEVmass

Use-After-Free in WebKit on Apple iOS, iPadOS, and macOS Allows Arbitrary Code Execution

CISA: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
13%p96
Published
()
KEV added
AI analysis

CVE-2021-30858 is a use-after-free memory corruption flaw (CWE-416) in the web content processing component (WebKit) of Apple iOS, iPadOS, and macOS, which Apple addressed with improved memory management. An attacker triggers it by getting a victim to process maliciously crafted web content, typically by visiting or being redirected to an attacker-controlled site, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 8.8 High, network vector with user interaction required). Anyone running affected builds of iOS, iPadOS, or macOS, or the affected component on Fedora or Debian Linux per the CPE data, is exposed, since virtually all Apple devices process web content by default. Apple acknowledged that the flaw was being actively exploited, reportedly as part of NSO Group's 'ForcedEntry' targeted zero-day espionage chain, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. No public proof-of-concept is known, but the confirmed in-the-wild use makes rapid patching urgent.

What to do: Update iPhones and iPads to iOS/iPadOS 14.8 and Macs to macOS Big Sur 11.6 immediately, and on Fedora or Debian apply the distribution's updated WebKit packages. Use MDM or inventory data to confirm no managed devices remain on pre-patch builds, since the flaw was exploited as a zero-day in targeted espionage operations. This is a CISA KEV entry (added 2021-11-03), so the catalog's required action of applying vendor updates is mandatory for federal agencies and strongly recommended for everyone else.

Affected
apple iPhone OS (iOS)versions prior to iOS 14.8 (fixed in iOS 14.8)
apple iPadOSversions prior to iPadOS 14.8 (fixed in iPadOS 14.8)
apple macOS (Big Sur)versions prior to macOS Big Sur 11.6 (fixed in 11.6)
fedoraproject Fedora Linux
Debian Linux
Estimated exposure
mass>1 billion users/devices (Apple's 1B+ active device base, all of which carry the vulnerable web-content code path) — Apple publicly reports more than one billion active iPhone, iPad, and Mac devices and the vulnerable web content processing path is present by default on all of them, so at the August/September 2021 disclosure the population running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
applefedoraprojectdebian
Products
ipados, iphone os, macos, fedora, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news