Apple Releases Urgent iPhone and iPad Updates to Patch New Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1782 | Race Condition Privilege Escalation in Apple iOS, macOS, watchOS, and tvOS A race condition caused by improper locking (CWE-667) in Apple's operating systems could allow local privilege escalation. The flaw is triggered by a malicious application already running on the device that exploits a timing race; exploitation requires only low local privileges and no user interaction, though the attack complexity is rated high. A successful attacker gains elevated privileges with high impact to the confidentiality, integrity, and availability of the device. Users of iPhone, iPad, Mac, Apple Watch, and Apple TV running versions earlier than iOS/iPadOS 14.4, macOS Big Sur 11.2 (or the 2021-001 security updates for Catalina and Mojave), watchOS 7.3, and tvOS 14.4 are affected. Apple reported the issue as actively exploited in the wild, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and no public proof-of-concept is known. Do: Upgrade to iOS/iPadOS 14.4, watchOS 7.3, and tvOS 14.4; on Macs, upgrade to macOS Big Sur 11.2 or apply Security Update 2021-001 for Catalina and Mojave. As an interim mitigation, avoid installing untrusted applications, since exploitation requires a malicious local app. This vulnerability is in the CISA KEV catalog, so organizations subject to the required action should verify that all managed Apple devices are running the patched versions. | 7.0 | 2% | KEV |
| masshundreds of millions of Apple devices (estimate based on Apple's active installed base exceeding 1 billion devices) | |
| CVE-2021-1870 +1 in the same advisory: …1871 | WebKit Logic Flaw Enables Remote Code Execution on iOS, iPadOS, and macOS CVE-2021-1870 is a logic flaw in Apple's WebKit browser engine, addressed in iOS 14.4, iPadOS 14.4, macOS Big Sur 11.2, and Security Update 2021-001 for Catalina and Mojave via improved restrictions. A remote attacker can trigger the flaw through hostile web content processed by WebKit on a vulnerable device, with no authentication or privileges required per the CVSS 3.1 network-vector scoring. Successful exploitation allows arbitrary code execution on the affected device. All users of iPhone OS/iPadOS prior to 14.4 and macOS prior to the listed fixes are affected, as WebKit ships with every Apple device, and WebKitGTK/Fedora users of the same engine are also potentially impacted. Apple reported the issue may have been actively exploited in the wild as a zero-day, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. Do: Upgrade iPhones/iPads to iOS/iPadOS 14.4, Macs to macOS Big Sur 11.2, and apply Security Update 2021-001 on Catalina and Mojave. Fedora/WebKitGTK users should install the distribution's updated WebKitGTK packages. The issue is on the CISA KEV list with a required action of applying vendor updates; no public PoC or specific mitigation is known, so patching is the primary remediation. | 9.8 | 8% | KEV |
| masson the order of 1+ billion Apple devices (WebKit ships in every iPhone, iPad, and Mac) | |
| CVE-2021-1879 | Universal XSS in Apple WebKit on iOS, iPadOS, and watchOS (Actively Exploited) CVE-2021-1879 is a universal cross-site scripting (UXSS) flaw in the WebKit browser engine affecting iOS, iPadOS, and watchOS, caused by an object-lifetime management error. An attacker can trigger it by convincing a user to process maliciously crafted web content (e.g., visiting an attacker-controlled page in Safari or another WebKit-based browser), allowing the attacker to bypass the same-origin policy and read or modify content of other sites in the browser. Successful exploitation is rated Medium severity (CVSS 6.1) because it requires user interaction, but it can leak sensitive data such as cookies, session tokens, or page content. Any user of an iPhone, iPad, or Apple Watch running software older than iOS 12.5.2, iOS 14.4.2/iPadOS 14.4.2, or watchOS 7.3.3 is affected. Apple reported that the issue may have been actively exploited in the wild at the time of patching, it is on the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), and public reporting tied its use to targeted campaigns (including Russian SVR-linked operations), though no public proof-of-concept is known. Do: Update devices to iOS 12.5.2 (older devices) or iOS 14.4.2/iPadOS 14.4.2, and Apple Watch devices to watchOS 7.3.3, per Apple's instructions. Because exploitation requires loading malicious web content in WebKit, avoid following untrusted web links on unpatched devices until updated; verify fleet-wide OS versions and confirm the fix, since this CVE is on the CISA KEV catalog with patching required. Check logs or browser history for signs of visits to attacker-controlled sites on devices that have since been updated, as no public proof-of-concept exists to test against. | 6.1 | 7% | KEV |
| masshundreds of millions of devices (Apple's active iPhone/iPad/watchOS install base was on the order of 1+ billion when patched; all unpatched devices are exposed… | |
| CVE-2021-30713 +1 in the same advisory: …30657 | Privacy Preferences (TCC) Bypass in Apple macOS, Actively Exploited CVE-2021-30713 is a permissions/authorization flaw (CWE-862) in Apple macOS that allows a malicious application already running on a machine to bypass the user's Privacy preferences, which govern which apps may access protected user data such as files, camera, microphone, and other consent-protected resources. The flaw is triggered locally: a malicious app that a user has launched can silently circumvent the Privacy controls without the usual approval prompt. Successful exploitation grants the attacker access to user data that should have required explicit user consent, with high impact to confidentiality, integrity, and availability per its 7.8 CVSS score. Any Mac running a version of macOS prior to the macOS Big Sur 11.4 fix is affected. Apple acknowledged a report that the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; the EPSS score of 7.0% (94th percentile) further indicates meaningful near-term exploitation risk. Do: Upgrade affected Macs to macOS Big Sur 11.4 or later immediately, as this issue is listed in CISA's KEV catalog with active exploitation confirmed. Audit Macs for unknown or recently installed applications that accessed protected data (files, camera, microphone) without a consent prompt, and prioritize internet-facing and high-value endpoints. Since Apple shipped this fix alongside other actively exploited zero-days in the same release cycle, ensure devices are fully updated rather than partially patched. | 7.8 group max | 7% | KEV |
| masstens of millions of Macs (macOS runs on an installed base estimated at 100M+ devices, and Big Sur was the current release when the patch shipped) | |
| CVE-2021-30661 | Use-After-Free in Apple WebKit Enables Code Execution via Malicious Web Content CVE-2021-30661 is a use-after-free flaw (CWE-416) in the storage handling of Apple's WebKit browser engine, affecting Safari, iOS, iPadOS, macOS, watchOS and tvOS. It is triggered simply by processing maliciously crafted web content, such as a victim loading a hostile web page, with no privileges or authentication required beyond user interaction. A successful attack can lead to arbitrary code execution on the affected device, with confidentiality, integrity and availability all rated high. Anyone running builds older than the fixed versions (Safari 14.1, iOS 12.5.3/14.5, iPadOS 14.5, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5) is potentially affected. Apple disclosed that the issue was actively exploited at the time of patching; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and EPSS assigns a roughly 4.5% probability of exploitation in the next 30 days. Do: Apply Apple's updates per vendor instructions: Safari 14.1, iOS 14.5/iPadOS 14.5 (or iOS 12.5.3 for older devices that cannot run iOS 14), macOS Big Sur 11.3, watchOS 7.4 and tvOS 14.5. Because the bug was exploited in the wild and is on CISA's KEV list, treat these patches as urgent and prioritize browsers and user workstations; verify that legacy devices still running pre-12.5.3 or pre-14.5 iOS builds are found and updated. No public proof-of-concept is known and patching is the primary mitigation. | 8.8 | 4% | KEV |
| masshundreds of millions to over a billion Apple devices across iOS, iPadOS, macOS, Safari, watchOS and tvOS (order-of-magnitude estimate) | |
| CVE-2021-30762 | Use-After-Free in Apple iOS WebKit Enables RCE via Crafted Web Content CVE-2021-30762 is a use-after-free memory-management flaw (CWE-416) in the WebKit browser engine used by Apple iOS. It is triggered when a vulnerable iPhone or iPad processes maliciously crafted web content, for example when a user browses to an attacker-controlled webpage. Successful exploitation allows arbitrary code execution with the privileges of the affected process, and the flaw scores 8.8 (high) on CVSS 3.1 (network vector, no privileges, user interaction required). Affected users are those running iOS versions that predate the fix, which Apple delivered in iOS 12.5.4 — an update targeting older devices still on the iOS 12 line. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns an 11.0% probability of exploitation within 30 days (96th percentile), though no public proof-of-concept is known. Do: Update affected iPhones and iPads to iOS 12.5.4 or later, and users on newer iOS release lines should install the corresponding current Apple update, since the defect is in the shared WebKit component; verify the installed version via Settings > General > Software Update. Because exploitation occurs through web content and the flaw is on the CISA KEV list, patch promptly and avoid clicking links from untrusted sources until devices are updated. | 8.8 | 11% | KEV |
| masshundreds of millions of iOS devices (WebKit runs in every iPhone; the iOS 12.5.4 fix targets the legacy-device population still on iOS 12 within Apple's 1B+… | |
| CVE-2021-30807 | Memory Corruption in Apple iOS, iPadOS, macOS, watchOS Allows Kernel Code Execution A memory corruption flaw (out-of-bounds write, CWE-787) exists in Apple's IOMobileFrameBuffer component, a core graphics/frame-buffer interface shared across iOS, iPadOS, macOS, and watchOS. It is triggered by an application running on the device interacting with the frame buffer interface, which corrupts kernel memory. Successful exploitation may allow the application to execute arbitrary code with kernel privileges, giving the attacker full control of the device and bypassing normal app sandboxing. Any device running an unpatched version of iOS, iPadOS, macOS, or watchOS is affected, which spans essentially the entire Apple device fleet. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild, and EPSS assigns a 28.8% probability of exploitation within 30 days (98th percentile); no public PoC is known. Do: Apply Apple's current software updates for iOS, iPadOS, macOS, and watchOS on all managed devices per vendor instructions, prioritizing internet-facing and corporate-owned iPhones, iPads, and Macs. Use MDM/endpoint inventory to identify devices on outdated OS builds and verify patch compliance, noting CISA added this flaw to the KEV catalog on 2021-11-03 with required action to apply updates per vendor instructions. | 7.8 | 29% | KEV |
| mass≈1 billion+ active Apple devices (core OS component present across the iOS/iPadOS/macOS/watchOS install base); number actually exploited unknown | |
| CVE-2021-30858 +1 in the same advisory: …30869 | Use-After-Free in WebKit on Apple iOS, iPadOS, and macOS Allows Arbitrary Code Execution CVE-2021-30858 is a use-after-free memory corruption flaw (CWE-416) in the web content processing component (WebKit) of Apple iOS, iPadOS, and macOS, which Apple addressed with improved memory management. An attacker triggers it by getting a victim to process maliciously crafted web content, typically by visiting or being redirected to an attacker-controlled site, and successful exploitation leads to arbitrary code execution on the victim's device (CVSS 3.1: 8.8 High, network vector with user interaction required). Anyone running affected builds of iOS, iPadOS, or macOS, or the affected component on Fedora or Debian Linux per the CPE data, is exposed, since virtually all Apple devices process web content by default. Apple acknowledged that the flaw was being actively exploited, reportedly as part of NSO Group's 'ForcedEntry' targeted zero-day espionage chain, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. No public proof-of-concept is known, but the confirmed in-the-wild use makes rapid patching urgent. Do: Update iPhones and iPads to iOS/iPadOS 14.8 and Macs to macOS Big Sur 11.6 immediately, and on Fedora or Debian apply the distribution's updated WebKit packages. Use MDM or inventory data to confirm no managed devices remain on pre-patch builds, since the flaw was exploited as a zero-day in targeted espionage operations. This is a CISA KEV entry (added 2021-11-03), so the catalog's required action of applying vendor updates is mandatory for federal agencies and strongly recommended for everyone else. | 8.8 group max | 13% | KEV |
| mass>1 billion users/devices (Apple's 1B+ active device base, all of which carry the vulnerable web-content code path) | |
| CVE-2021-30860 +1 in the same advisory: …30883 | Integer Overflow in Apple PDF Processing Enables Arbitrary Code Execution (CVE-2021-30860) CVE-2021-30860 is an integer overflow (CWE-190) in PDF processing across Apple's platforms that was addressed with improved input validation. It is triggered when a device processes a maliciously crafted PDF — notably when a PDF is rendered after being received via messaging — and successful exploitation allows arbitrary code execution in the context of the PDF renderer. Affected products include iOS/iPadOS, macOS (Big Sur and Catalina), and watchOS, as well as the Xpdf and Poppler PDF libraries, which share lineage with the vulnerable code. Apple confirmed the issue was being actively exploited in the wild, and public reporting ties it to NSO Group's 'ForcedEntry' exploit chain used to deliver Pegasus spyware; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03. Given the very high EPSS score (76%, 99th percentile) and confirmed active exploitation, defenders should treat this as a high-priority patch. Do: Update iPhones/iPads to iOS/iPadOS 14.8, Macs to macOS Big Sur 11.6 (or apply Security Update 2021-005 Catalina), and Apple Watch to watchOS 7.6.2 immediately, and patch Poppler/Xpdf through distribution or vendor updates. Because the flaw was exploited via crafted PDFs delivered through messaging (ForcedEntry/Pegasus), organizations and individuals at risk of targeted spyware should also review devices for signs of compromise. CISA KEV requires applying updates per vendor instructions; prioritize internet-connected and high-value user endpoints. | 7.8 | 76% | KEV |
| mass>1 billion active Apple devices (iPhones, iPads, Macs, Apple Watches), plus Poppler present by default on most Linux desktops and servers |
Full article528 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 12, 2021
Apple on Monday released a security update for iOS and iPad to address a critical vulnerability that it says is being exploited in the wild, making it the 17th zero-day flaw the company has addressed in its products since the start of the year.
The weakness, assigned the identifier CVE-2021-30883, concerns a memory corruption issue in the "IOMobileFrameBuffer" component that could allow an application to execute arbitrary code with kernel privileges. Crediting an anonymous researcher for reporting the vulnerability, Apple said it's "aware of a report that this issue may have been actively exploited."
Technical specifics about the flaw and the nature of the attacks remain unavailable as yet, as is the identity of the threat actor, so as to allow a majority of the users to apply the patch and prevent other adversaries from weaponizing the vulnerability. The iPhone maker said it addressed the issue with improved memory handling.
But soon after the advisory was released, security researcher Saar Amar shared additional details, and a proof-of-concept (PoC) exploit, noting that "this attack surface is highly interesting because it's accessible from the app sandbox (so it's great for jailbreaks) and many other processes, making it a good candidate for LPEs exploits in chains."
CVE-2021-30883 is also the second zero-day impacting IOMobileFrameBuffer after Apple addressed a similar, anonymously reported memory corruption issue (CVE-2021-30807) in July 2021, raising the possibility that the two flaws could be related. With the latest fix, the company has resolved a record 17 zero-days to date in 2021 alone —
- CVE-2021-1782 (Kernel) - A malicious application may be able to elevate privileges
- CVE-2021-1870 (WebKit) - A remote attacker may be able to cause arbitrary code execution
- CVE-2021-1871 (WebKit) - A remote attacker may be able to cause arbitrary code execution
- CVE-2021-1879 (WebKit) - Processing maliciously crafted web content may lead to universal cross-site scripting
- CVE-2021-30657 (System Preferences) - A malicious application may bypass Gatekeeper checks
- CVE-2021-30661 (WebKit Storage) - Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2021-30663 (WebKit) - Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2021-30665 (WebKit) - Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2021-30666 (WebKit) - Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2021-30713 (TCC framework) - A malicious application may be able to bypass Privacy preferences
- CVE-2021-30761 (WebKit) - Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2021-30762 (WebKit) - Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2021-30807 (IOMobileFrameBuffer) - An application may be able to execute arbitrary code with kernel privileges
- CVE-2021-30858 (WebKit) - Processing maliciously crafted web content may lead to arbitrary code execution
- CVE-2021-30860 (CoreGraphics) - Processing a maliciously crafted PDF may lead to arbitrary code execution
- CVE-2021-30869 (XNU) - A malicious application may be able to execute arbitrary code with kernel privileges
Apple iPhone and iPad users are highly recommended to update to the latest version (iOS 15.0.2 and iPad 15.0.2) to mitigate the security vulnerability.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/10/apple-releases-urgent-iphone-and-ipad.html