Executive brief
A logic issue in the WebKit engine allows remote attackers to execute arbitrary code on affected Apple devices. The vulnerability stems from insufficient restrictions during HTML processing and has been reported as being actively exploited in the wild.
Affected products
- Apple iOS before 14.4
- Apple iPadOS before 14.4
- Apple macOS Big Sur before 11.2
- Apple macOS Catalina before Security Update 2021-001
- Apple macOS Mojave before Security Update 2021-001
- Apple WebKit
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-01-26: patched: Fixed in iOS 14.4, iPadOS 14.4, and macOS Big Sur 11.2
- 2021-11-03: exploited: Apple is aware of reports of active exploitation.