CVE-2021-30858
KEVmassUse-After-Free in WebKit on Apple iOS, iPadOS, and macOS Allows Arbitrary Code Execution
CISA: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability
CVE-2021-30858 is a use-after-free memory corruption flaw (CWE-416) in the web content processing component (WebKit) of Apple iOS, iPadOS, and macOS, which Apple addressed with improved memory management. An attacker triggers it by getting a victim to process maliciously crafted web content, typically by visiting or being redirected to an attacker-controlled site, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 8.8 High, network vector with user interaction required). Anyone running affected builds of iOS, iPadOS, or macOS, or the affected component on Fedora or Debian Linux per the CPE data, is exposed, since virtually all Apple devices process web content by default. Apple acknowledged that the flaw was being actively exploited, reportedly as part of NSO Group's 'ForcedEntry' targeted zero-day espionage chain, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. No public proof-of-concept is known, but the confirmed in-the-wild use makes rapid patching urgent.
What to do: Update iPhones and iPads to iOS/iPadOS 14.8 and Macs to macOS Big Sur 11.6 immediately, and on Fedora or Debian apply the distribution's updated WebKit packages. Use MDM or inventory data to confirm no managed devices remain on pre-patch builds, since the flaw was exploited as a zero-day in targeted espionage operations. This is a CISA KEV entry (added 2021-11-03), so the catalog's required action of applying vendor updates is mandatory for federal agencies and strongly recommended for everyone else.
| apple iPhone OS (iOS) | versions prior to iOS 14.8 (fixed in iOS 14.8) |
| apple iPadOS | versions prior to iPadOS 14.8 (fixed in iPadOS 14.8) |
| apple macOS (Big Sur) | versions prior to macOS Big Sur 11.6 (fixed in 11.6) |
| fedoraproject Fedora Linux | — |
| Debian Linux | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
- Affected
- Apple iOS, iPadOS, and macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- applefedoraprojectdebian
- Products
- ipados, iphone os, macos, fedora, debian linux
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H