Executive brief
Apple iOS WebKit contains a memory corruption vulnerability (specifically an out-of-bounds write) when processing maliciously crafted web content. Successful exploitation allows for arbitrary code execution on the affected device. Apple has acknowledged reports that this vulnerability may have been actively exploited in the wild.
Affected products
- Apple iOS up to (excluding) 12.5.4
- Apple WebKit
Timeline
- 2021-06-14: patched: Issue addressed in iOS 12.5.4
- 2021-09-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Apple reported awareness of active exploitation.