Executive brief
Apple iOS WebKit contains a buffer overflow vulnerability due to improper memory handling when processing maliciously crafted web content. Successful exploitation allows for arbitrary code execution on the affected device. Apple has acknowledged reports that this vulnerability may have been actively exploited in the wild.
Affected products
- Apple iOS up to (excluding) 12.5.3
- Apple WebKit
Timeline
- 2021-09-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-05-03: patched: Fixed in iOS 12.5.3 (based on Apple advisory HT212341)
- 2021-11-03: advisory: Advisory published date provided in text
- exploited: Apple is aware of reports of active exploitation.