Junglewise Threat Intelligence

CVE-2021-30665: Apple Multiple Products WebKit Memory Corruption Vulnerability

CVE-2021-30665 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple iPadOS, Apple watchOS, Apple Tvos, Apple Multiple Products. Vendors: Apple.

Executive brief

A memory corruption vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue stems from improper state management and has been reported as being actively exploited in the wild.

Affected products

  • Apple WebKit
  • Apple iOS < 14.5.1, < 12.5.3
  • Apple iPadOS < 14.5.1
  • Apple macOS Big Sur < 11.3.1
  • Apple tvOS < 14.6
  • Apple watchOS < 7.4.1

Timeline

  • 2021-09-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-05-03: patched: Apple released updates for iOS, iPadOS, and macOS to address the issue.
  • 2021-05-14: exploited: Apple reported awareness of active exploitation.

Related threats