cbcvebase.
CVE-2021-1879
published 2021-04-02

CVE-2021-1879: This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing…

PriorityP179medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
7.08%
93.5th percentile
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..

Affected

7 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < 12.512.5
appleios_and_ipados>= unspecified < 14.414.4
appleipados< 14.4.214.4.2
appleiphone_os< 12.5.212.5.2
appleiphone_os>= 13.0 < 14.4.214.4.2
applewatchos< 7.3.37.3.3
applewatchos>= unspecified < 7.37.3

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://track-adv[.]com/market-analytics.php?pc=1
domaintrack-adv[.]com
domainceo-adviser[.]com
urlhttps://ceo-adviser[.]com/fb-connect.php?online=1
urlhttps://track-adv[.]com/analytics.php?personalization_id=
otherwebmail.mfa.gov.mn/owa/auth
otherIndexedDB database name: minus
  • The cookie stealer exploit sets m_universalAccess to 1 inside the SecurityOrigin class by traversing a set of pointers, then overwrites Document URLs and m_url field of a websocket to exfiltrate authentication cookies. Detect anomalous WebSocket connections from WebKit processes to attacker-controlled IPs following DOM manipulation.
  • On more recent iOS versions the payload calls WebCore::NetworkStorageSession::getAllCookies() to bulk-collect all cookies before exfiltration. Monitor for this function being invoked outside of normal browser activity.
  • The C2 replies with an AES-encrypted next stage payload; the client makes a follow-up request with gcr=1 as a URL parameter to retrieve the AES decryption key. Detect HTTP requests containing the gcr=1 parameter to suspicious domains.
  • The exploit failure mode sends failure information back to the C2 and then attempts to crash the browser with an out-of-memory error. Unexpected WebKit/Safari OOM crashes combined with prior outbound network requests to unknown IPs may indicate exploitation attempts.
  • The exploit includes a function named dacsiloscope that uses read/write primitives to collect device information (e.g., PAC support) to decide whether to deploy the cookie stealer payload. Presence of this function name in JavaScript or memory may indicate the exploit framework.
  • The watering hole delivery mechanism uses a hidden iframe injected into legitimate government websites. Monitor for iframe elements loading cross-origin content from unexpected domains on trusted government sites.
  • APT29 used LinkedIn Messaging to deliver malicious links targeting government officials from western European countries in the 2021 CVE-2021-1879 campaign. Monitor for LinkedIn messages containing URLs leading to exploit infrastructure.
  • ·The iOS WebKit exploit (CVE-2021-1879 cookie stealer framework re-used in 2023-2024) only affects iOS versions 16.6.1 or older; devices with Lockdown Mode enabled are not affected even on vulnerable iOS versions.

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vulncheck6.1MEDIUM
cisa6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.