Junglewise Threat Intelligence

CVE-2021-30762: Apple iOS WebKit Use-After-Free Vulnerability

CVE-2021-30762 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Vendors: Apple.

Executive brief

Apple iOS WebKit contains a use-after-free vulnerability in its HTML parser. Processing maliciously crafted web content can lead to arbitrary code execution. Apple has acknowledged reports that this vulnerability has been actively exploited in the wild.

Affected products

  • Apple iOS versions up to (excluding) 12.5.4
  • Apple WebKit

Timeline

  • 2021-09-08: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-06-14: patched: Fixed in iOS 12.5.4
  • exploited: Apple is aware of reports of active exploitation.