ZeroHour

CVE-2021-30952

KEV PoC mass1

CVE-2021-30952: Integer Overflow in Apple Safari/WebKit Allows Arbitrary Code Execution

CISA: Apple Multiple Products Integer Overflow or Wraparound Vulnerability

CVSS 3.1
7.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2021-30952 is an integer overflow (CWE-190) in the WebKit web engine used across Apple's platforms — the same engine shipped as WebKitGTK and WPE WebKit on Linux — which Apple addressed with improved input validation. An attacker triggers it by persuading a user to process maliciously crafted web content, such as loading an attacker-controlled web page, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 7.8 high, with a local attack vector requiring user interaction). All users of unpatched affected platforms are exposed: iOS/iPadOS before 15.2, macOS Monterey before 12.1, Safari before 15.2, tvOS before 15.2, and watchOS before 8.3, plus Fedora/Debian systems running unpatched WebKitGTK/WPE WebKit. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use: unknown), and Google threat intelligence documented it as part of the 'Coruna' iOS exploit kit — 23 exploits across five chains, used for financial crime and targeting devices on older iOS versions such as iOS 13. EPSS assigns a 7.0% probability of exploitation within 30 days (94th percentile).

What to do: Upgrade to iOS/iPadOS 15.2, macOS Monterey 12.1, Safari 15.2, tvOS 15.2, and watchOS 8.3; devices on older iOS branches (e.g., iOS 13, targeted by the Coruna exploit kit) should immediately apply Apple's emergency fixes for those versions. On Fedora and Debian, pull the latest WebKitGTK/WPE WebKit security updates through the distro package channels. Federal agencies must meet the BOD 22-01 remediation deadline for this KEV entry, and should inventory for Apple devices that cannot reach a patched version and replace or isolate them.

Affected
Apple iOS (iPhone OS)all versions prior to iOS 15.2; Apple also issued emergency fixes for older iOS branches per vendor reporting
Apple iPadOSall versions prior to iPadOS 15.2
Apple macOS Montereyversions prior to 12.1
Apple Safariversions prior to 15.2
Apple tvOSversions prior to 15.2
Apple watchOSversions prior to 8.3
WebKitGTK
WPE WebKit
Fedora Linux
Debian Linux
Estimated exposure
mass≈1 billion+ Apple devices (iOS/iPadOS/macOS/tvOS/watchOS/Safari install base), with practical residual exposure concentrated in legacy iPhones/iPads on old iOS… — Estimated from Apple's publicly reported installed base of more than one billion active devices, where WebKit/Safari is the default web engine on every Apple platform, plus WebKitGTK/WPE WebKit users on Fedora and Debian desktops; the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
applefedoraprojectdebianwebkitgtkwpewebkit
Products
safari, ipados, iphone os, macos, tvos, watchos, fedora, debian linux, webkitgtk, wpe webkit
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news