Executive brief
A logic vulnerability in the WebKit engine allows for remote code execution when processing maliciously crafted web content. The issue was addressed by improving restrictions within the logic flow. This vulnerability has been reported as being actively exploited in the wild.
Affected products
- Apple WebKit
- Apple iOS before 14.4
- Apple iPadOS before 14.4
- Apple macOS Big Sur before 11.2
- Apple macOS Catalina Security Update 2021-001
- Apple macOS Mojave Security Update 2021-001
Timeline
- 2021-01-26: patched: Fixed in iOS 14.4, iPadOS 14.4, macOS Big Sur 11.2, and Security Updates for Catalina and Mojave.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: NVD publication date.
- 2021-01-26: exploited: Apple reported awareness of active exploitation at time of patch release.