Executive brief
A use-after-free vulnerability in Apple WebKit Storage allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed through improved memory management across multiple Apple operating systems and the Safari browser.
Affected products
- Apple WebKit Storage
- Apple Safari before 14.1
- Apple iOS before 12.5.3, 14.0 to 14.5
- Apple iPadOS before 14.5
- Apple watchOS before 7.4
- Apple tvOS before 14.5
- Apple macOS Big Sur 11.0 to 11.3
Timeline
- 2021-09-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- exploited: Apple is aware of reports that this issue may have been actively exploited.
- patched: Fixed in Safari 14.1, iOS 12.5.3, iOS 14.5, iPadOS 14.5, watchOS 7.4, tvOS 14.5, and macOS Big Sur 11.3.