Junglewise Threat Intelligence

CVE-2021-1879: Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

CVE-2021-1879 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2021-11-03

Technologies: Apple watchOS, Apple iPadOS. Vendors: Apple.

Executive brief

Apple WebKit contains a universal cross-site scripting (XSS) vulnerability due to improper management of object lifetimes. Processing maliciously crafted web content can allow an attacker to execute scripts across different domains, impacting various HTML parsers and browsers that rely on WebKit.

Affected products

  • Apple iOS Before 12.5.2, 13.0 to 14.4.2
  • Apple iPadOS Before 14.4.2
  • Apple watchOS Before 7.3.3
  • Apple WebKit

Timeline

  • 2021-04-02: disclosed: NVD Published Date
  • 2021-04-09: patched: Initial NIST analysis and patch information recorded
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Apple is aware of reports that this issue may have been actively exploited.

Related threats