ZeroHour
Security Affairspublished ()ingested @securityaffairs

Apple addresses three zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30661
+2 in the same advisory: …30665 …30663
Use-After-Free in Apple WebKit Enables Code Execution via Malicious Web Content

CVE-2021-30661 is a use-after-free flaw (CWE-416) in the storage handling of Apple's WebKit browser engine, affecting Safari, iOS, iPadOS, macOS, watchOS and tvOS. It is triggered simply by processing maliciously crafted web content, such as a victim loading a hostile web page, with no privileges or authentication required beyond user interaction. A successful attack can lead to arbitrary code execution on the affected device, with confidentiality, integrity and availability all rated high. Anyone running builds older than the fixed versions (Safari 14.1, iOS 12.5.3/14.5, iPadOS 14.5, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5) is potentially affected. Apple disclosed that the issue was actively exploited at the time of patching; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and EPSS assigns a roughly 4.5% probability of exploitation in the next 30 days.

Do: Apply Apple's updates per vendor instructions: Safari 14.1, iOS 14.5/iPadOS 14.5 (or iOS 12.5.3 for older devices that cannot run iOS 14), macOS Big Sur 11.3, watchOS 7.4 and tvOS 14.5. Because the bug was exploited in the wild and is on CISA's KEV list, treat these patches as urgent and prioritize browsers and user workstations; verify that legacy devices still running pre-12.5.3 or pre-14.5 iOS builds are found and updated. No public proof-of-concept is known and patching is the primary mitigation.

8.84% KEV
  • Apple Safari versions prior to 14.1
  • Apple iPhone OS (iOS) versions prior to 14.5; versions prior to 12.5.3 on legacy devices
  • Apple iPadOS versions prior to 14.5
  • +3 more
masshundreds of millions to over a billion Apple devices across iOS, iPadOS, macOS, Safari, watchOS and tvOS (order-of-magnitude estimate)
CVE-2021-30666
WebKit Buffer Overflow in Apple iOS Allows Code Execution via Malicious Web Content

CVE-2021-30666 is a buffer overflow (CWE-119) in the WebKit web engine on Apple iOS, caused by improper memory handling. It is triggered remotely when the device processes maliciously crafted web content, meaning a victim only has to encounter attacker-controlled web pages or web content for the flaw to be reached (network vector with user interaction, per the CVSS 3.1 score of 8.8). Successful exploitation can lead to arbitrary code execution on the device with full confidentiality, integrity, and availability impact. All iOS devices running versions before the iOS 12.5.3 fix are affected, with iOS 12.5.3 serving devices that remain on Apple's legacy iOS 12 branch. Apple reported the bug was being actively exploited in the wild when it was patched, CISA added it to the KEV on 2021-11-03, and EPSS assigns a 3% probability of exploitation within 30 days (87th percentile), though no public PoC is known.

Do: Upgrade affected devices to iOS 12.5.3 or later, and have devices on newer iOS branches take the corresponding current-branch iOS security updates Apple released at the same time, per CISA's required action to apply updates per vendor instructions. Because the attack vector is web content and no public workaround is documented, patching WebKit is the primary defense, so prioritize older hardware that only receives iOS 12.5.x updates and verify fleet-wide compliance.

8.83% KEV
  • Apple iPhone OS (iOS) All versions prior to iOS 12.5.3 (fix released in the iOS 12.5.x legacy-branch update; source data specifies no other version ranges)
masshundreds of millions of iOS devices (global iPhone install base exceeds 1 billion; devices limited to the legacy iOS 12 branch are in the tens of millions)
Full article226 words · extracted from securityaffairs.com · click to collapse

Apple has released security updates to patch three zero-days in the WebKit, the Apple’s browser engine, and fixed a zero-day exploited in the wild.

Apple released security updates to address four zero-day vulnerabilities impacting WebKit, which is used by multiple products of the IT giant, including iPadOS, tvOS, and watchOS.

The WebKit browser engine is used by multiple products to display web content.

Apple fixed the three suspected WebKit zero-day flaws, tracked as CVE-2021-30663, CVE-2021-30665, and CVE-2021-30666, with the release of macOS Big Sur 11.3.1, iOS 12.5.3, iOS 14.5.1, iPadOS 14.5.1, and watchOS 7.4.1. The company also fixed the fourth issue, tracked as CVE-2021-30661, with the release of iOS 12.5.3. Apple first patched this flaw in iOS, iPadOSwatchOS, and tvOS.

“Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.” reads the description provided by Apple for all the flaws.

The tech giant did not share technical details about the flaws and how to trigger them.

All the bugs were reported to Apple by researcher @dnpushme from Qihoo 360 ATA.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, WebKit)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/117500/security/apple-webkit-zero-day-flaws.html