Executive brief
A use-after-free vulnerability in Apple WebKit allows for arbitrary code execution when processing maliciously crafted web content. The flaw stems from improper memory management and affects various Apple operating systems and browsers, as well as third-party applications utilizing WebKit for HTML parsing.
Affected products
- Apple iOS Before 14.8
- Apple iPadOS Before 14.8
- Apple macOS Big Sur Before 11.6
- Apple WebKit
- Apple Safari
Timeline
- 2021-09-13: patched: Fixed in iOS 14.8, iPadOS 14.8, and macOS Big Sur 11.6
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed: NVD publication date
- 2021-11-03: exploited: Apple and CISA confirmed reports of active exploitation in the wild.