Junglewise Threat Intelligence

CVE-2021-30761: Apple iOS WebKit Memory Corruption Vulnerability

CVE-2021-30761 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Vendors: Apple.

Executive brief

Apple iOS WebKit contains a memory corruption vulnerability (specifically an out-of-bounds write) when processing maliciously crafted web content. Successful exploitation allows for arbitrary code execution on the affected device. Apple has acknowledged reports that this vulnerability may have been actively exploited in the wild.

Affected products

  • Apple iOS up to (excluding) 12.5.4
  • Apple WebKit

Timeline

  • 2021-06-14: patched: Issue addressed in iOS 12.5.4
  • 2021-09-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Apple reported awareness of active exploitation.