Executive brief
Apple iOS WebKit contains a use-after-free vulnerability in its HTML parser. Processing maliciously crafted web content can lead to arbitrary code execution. Apple has acknowledged reports that this vulnerability has been actively exploited in the wild.
Affected products
- Apple iOS versions up to (excluding) 12.5.4
- Apple WebKit
Timeline
- 2021-09-08: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-06-14: patched: Fixed in iOS 12.5.4
- exploited: Apple is aware of reports of active exploitation.