Apple releases fixes for three WebKit zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-30661 | Use-After-Free in Apple WebKit Enables Code Execution via Malicious Web Content CVE-2021-30661 is a use-after-free flaw (CWE-416) in the storage handling of Apple's WebKit browser engine, affecting Safari, iOS, iPadOS, macOS, watchOS and tvOS. It is triggered simply by processing maliciously crafted web content, such as a victim loading a hostile web page, with no privileges or authentication required beyond user interaction. A successful attack can lead to arbitrary code execution on the affected device, with confidentiality, integrity and availability all rated high. Anyone running builds older than the fixed versions (Safari 14.1, iOS 12.5.3/14.5, iPadOS 14.5, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5) is potentially affected. Apple disclosed that the issue was actively exploited at the time of patching; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and EPSS assigns a roughly 4.5% probability of exploitation in the next 30 days. Do: Apply Apple's updates per vendor instructions: Safari 14.1, iOS 14.5/iPadOS 14.5 (or iOS 12.5.3 for older devices that cannot run iOS 14), macOS Big Sur 11.3, watchOS 7.4 and tvOS 14.5. Because the bug was exploited in the wild and is on CISA's KEV list, treat these patches as urgent and prioritize browsers and user workstations; verify that legacy devices still running pre-12.5.3 or pre-14.5 iOS builds are found and updated. No public proof-of-concept is known and patching is the primary mitigation. | 8.8 | 4% | KEV |
| masshundreds of millions to over a billion Apple devices across iOS, iPadOS, macOS, Safari, watchOS and tvOS (order-of-magnitude estimate) | |
| CVE-2021-30666 | WebKit Buffer Overflow in Apple iOS Allows Code Execution via Malicious Web Content CVE-2021-30666 is a buffer overflow (CWE-119) in the WebKit web engine on Apple iOS, caused by improper memory handling. It is triggered remotely when the device processes maliciously crafted web content, meaning a victim only has to encounter attacker-controlled web pages or web content for the flaw to be reached (network vector with user interaction, per the CVSS 3.1 score of 8.8). Successful exploitation can lead to arbitrary code execution on the device with full confidentiality, integrity, and availability impact. All iOS devices running versions before the iOS 12.5.3 fix are affected, with iOS 12.5.3 serving devices that remain on Apple's legacy iOS 12 branch. Apple reported the bug was being actively exploited in the wild when it was patched, CISA added it to the KEV on 2021-11-03, and EPSS assigns a 3% probability of exploitation within 30 days (87th percentile), though no public PoC is known. Do: Upgrade affected devices to iOS 12.5.3 or later, and have devices on newer iOS branches take the corresponding current-branch iOS security updates Apple released at the same time, per CISA's required action to apply updates per vendor instructions. Because the attack vector is web content and no public workaround is documented, patching WebKit is the primary defense, so prioritize older hardware that only receives iOS 12.5.x updates and verify fleet-wide compliance. | 8.8 | 3% | KEV |
| masshundreds of millions of iOS devices (global iPhone install base exceeds 1 billion; devices limited to the legacy iOS 12 branch are in the tens of millions) |
Full article285 words · extracted from therecord.media · click to collapse
Apple has released today security updates for multiple products to patch three zero-days and roll out additional patches for a fourth that the company said they might have been exploited in the wild. All four zero-days impact WebKit—the web page rendering engine at the heart of the company's Safari web browser. While Safari is available only for iOS and macOS, the WebKit engine is available as a built-in component on most of the company's products, including iPadOS, tvOS, and watchOS, where it is used to display web content inside a no-UI borderless window, without having to load a full browser app. Today, Apple released macOS Big Sur 11.3.1, iOS 12.5.3, iOS 14.5.1, iPadOS 14.5.1, and watchOS 7.4.1 to patch three suspected WebKit zero-days, tracked as CVE-2021-30663, CVE-2021-30665, and CVE-2021-30666. In addition, the iOS 12.5.3 update also includes a fix for CVE-2021-30661, a fourth suspected WebKit zero-day that Apple first patched last Monday in iOS, iPadOS, watchOS, and tvOS. Typical to its regular security policy, Apple has not shared details about the potential attacks. All four WebKit bugs have the same description: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. Apple credited Qihoo 360 ATA researcher @dnpushme with discovering all four bugs. To Be Continue... https://t.co/5XOz0he35F In 2020, the same Qihoo 360 ATA team and the same researcher also found similar Firefox and Internet Explorer zero-days abused in the wild by a threat actor known as Dark Hotel. The four fixes also come after Apple patched another WebKit zero-day—this one discovered by Google— on March 26.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/apple-releases-fixes-for-three-webkit-zero-days-additional-patches-for-a-fourth