Executive brief
An integer overflow vulnerability in WebKit's HTML processing was addressed with improved input validation. Processing maliciously crafted web content may lead to arbitrary code execution on affected Apple devices and software.
Affected products
- Apple iOS Before 14.5.1, and 12.5.3
- Apple iPadOS Before 14.5.1
- Apple tvOS Before 14.6
- Apple Safari Before 14.1.1
- Apple macOS Big Sur Before 11.3.1
- Apple WebKit All versions used in affected OS releases
Timeline
- 2021-05-03: patched: Fixed in iOS 14.5.1, iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed: Publicly published in NVD