CVE-2021-30952
KEV PoC mass1CVE-2021-30952: Integer Overflow in Apple Safari/WebKit Allows Arbitrary Code Execution
CISA: Apple Multiple Products Integer Overflow or Wraparound Vulnerability
CVE-2021-30952 is an integer overflow (CWE-190) in the WebKit web engine used across Apple's platforms — the same engine shipped as WebKitGTK and WPE WebKit on Linux — which Apple addressed with improved input validation. An attacker triggers it by persuading a user to process maliciously crafted web content, such as loading an attacker-controlled web page, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 7.8 high, with a local attack vector requiring user interaction). All users of unpatched affected platforms are exposed: iOS/iPadOS before 15.2, macOS Monterey before 12.1, Safari before 15.2, tvOS before 15.2, and watchOS before 8.3, plus Fedora/Debian systems running unpatched WebKitGTK/WPE WebKit. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use: unknown), and Google threat intelligence documented it as part of the 'Coruna' iOS exploit kit — 23 exploits across five chains, used for financial crime and targeting devices on older iOS versions such as iOS 13. EPSS assigns a 7.0% probability of exploitation within 30 days (94th percentile).
What to do: Upgrade to iOS/iPadOS 15.2, macOS Monterey 12.1, Safari 15.2, tvOS 15.2, and watchOS 8.3; devices on older iOS branches (e.g., iOS 13, targeted by the Coruna exploit kit) should immediately apply Apple's emergency fixes for those versions. On Fedora and Debian, pull the latest WebKitGTK/WPE WebKit security updates through the distro package channels. Federal agencies must meet the BOD 22-01 remediation deadline for this KEV entry, and should inventory for Apple devices that cannot reach a patched version and replace or isolate them.
| Apple iOS (iPhone OS) | all versions prior to iOS 15.2; Apple also issued emergency fixes for older iOS branches per vendor reporting |
| Apple iPadOS | all versions prior to iPadOS 15.2 |
| Apple macOS Monterey | versions prior to 12.1 |
| Apple Safari | versions prior to 15.2 |
| Apple tvOS | versions prior to 15.2 |
| Apple watchOS | versions prior to 8.3 |
| WebKitGTK | — |
| WPE WebKit | — |
| Fedora Linux | — |
| Debian Linux | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- applefedoraprojectdebianwebkitgtkwpewebkit
- Products
- safari, ipados, iphone os, macos, tvos, watchos, fedora, debian linux, webkitgtk, wpe webkit
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H