Junglewise Threat Intelligence

CVE-2021-30858: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

CVE-2021-30858 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple macOS, Apple Safari, Apple iPadOS. Vendors: Apple.

Executive brief

A use-after-free vulnerability in Apple WebKit allows for arbitrary code execution when processing maliciously crafted web content. The flaw stems from improper memory management and affects various Apple operating systems and browsers, as well as third-party applications utilizing WebKit for HTML parsing.

Affected products

  • Apple iOS Before 14.8
  • Apple iPadOS Before 14.8
  • Apple macOS Big Sur Before 11.6
  • Apple WebKit
  • Apple Safari

Timeline

  • 2021-09-13: patched: Fixed in iOS 14.8, iPadOS 14.8, and macOS Big Sur 11.6
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: NVD publication date
  • 2021-11-03: exploited: Apple and CISA confirmed reports of active exploitation in the wild.

Related threats