CVE-2021-1879
published 2021-04-02CVE-2021-1879: This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing…
PriorityP179medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
7.08%
93.5th percentile
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < 12.5 | 12.5 |
| apple | ios_and_ipados | >= unspecified < 14.4 | 14.4 |
| apple | ipados | < 14.4.2 | 14.4.2 |
| apple | iphone_os | < 12.5.2 | 12.5.2 |
| apple | iphone_os | >= 13.0 < 14.4.2 | 14.4.2 |
| apple | watchos | < 7.3.3 | 7.3.3 |
| apple | watchos | >= unspecified < 7.3 | 7.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →The cookie stealer exploit sets m_universalAccess to 1 inside the SecurityOrigin class by traversing a set of pointers, then overwrites Document URLs and m_url field of a websocket to exfiltrate authentication cookies. Detect anomalous WebSocket connections from WebKit processes to attacker-controlled IPs following DOM manipulation. ↗
- →On more recent iOS versions the payload calls WebCore::NetworkStorageSession::getAllCookies() to bulk-collect all cookies before exfiltration. Monitor for this function being invoked outside of normal browser activity. ↗
- →The C2 replies with an AES-encrypted next stage payload; the client makes a follow-up request with gcr=1 as a URL parameter to retrieve the AES decryption key. Detect HTTP requests containing the gcr=1 parameter to suspicious domains. ↗
- →The exploit failure mode sends failure information back to the C2 and then attempts to crash the browser with an out-of-memory error. Unexpected WebKit/Safari OOM crashes combined with prior outbound network requests to unknown IPs may indicate exploitation attempts. ↗
- →The exploit includes a function named dacsiloscope that uses read/write primitives to collect device information (e.g., PAC support) to decide whether to deploy the cookie stealer payload. Presence of this function name in JavaScript or memory may indicate the exploit framework. ↗
- →The watering hole delivery mechanism uses a hidden iframe injected into legitimate government websites. Monitor for iframe elements loading cross-origin content from unexpected domains on trusted government sites. ↗
- →APT29 used LinkedIn Messaging to deliver malicious links targeting government officials from western European countries in the 2021 CVE-2021-1879 campaign. Monitor for LinkedIn messages containing URLs leading to exploit infrastructure. ↗
- ·The iOS WebKit exploit (CVE-2021-1879 cookie stealer framework re-used in 2023-2024) only affects iOS versions 16.6.1 or older; devices with Lockdown Mode enabled are not affected even on vulnerable iOS versions. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vulncheck6.1MEDIUM
cisa6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
cisa·2021-11-03·CVSS 6.1
CVE-2021-1879 [MEDIUM] CWE-79 Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
Vulnerability: Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
Affected: Apple iOS, iPadOS, and watchOS
Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-1879
Remediation Due Date: 2021-11-17
GHSA
GHSA-qhqp-qw35-f96r: This issue was addressed by improved management of object lifetimes
ghsa_unreviewed·2022-05-24
CVE-2021-1879 [MEDIUM] CWE-79 GHSA-qhqp-qw35-f96r: This issue was addressed by improved management of object lifetimes
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
Project0
The More You Know, The More You Know You Don’t Know - Project Zero
project_zero·2022-04-01
CVE-2016-4654 The More You Know, The More You Know You Don’t Know - Project Zero
A Year in Review of 0-days Used In-the-Wild in 2021
Posted by Maddie Stone, Google Project Zero
This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019]. Each year we’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what we think the trends and takeaways are. The goal of this report is not to detail each individual exploit, but instead to analyze the exploits from the year as a group, looking for trends, gaps, lessons learned, successes, etc. If you’re interested in the analysis of individual exploits, please check out our root cause analysis repository.
We perform and share this analysis in order to make 0-day hard. We want it to be more costly, more resource intensive, and overall more difficult for
VulnCheck
Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
vulncheck·2021·CVSS 6.1
CVE-2021-1879 [MEDIUM] CWE-79 Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple iOS, iPadOS, and watchOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/kb/HT212256; https://support.apple.com/kb/HT212257; https://support.apple.com/kb/HT212258; https://www.microsoft.com/security/blog/20
Project0
Project Zero RCA: CVE-2021-1879: Use-After-Free in QuickTimePluginReplacement
project_zero·CVSS 6.1
CVE-2021-1879 [MEDIUM] Project Zero RCA: CVE-2021-1879: Use-After-Free in QuickTimePluginReplacement
# CVE-2021-1879: Use-After-Free in QuickTimePluginReplacement
*Clement Lecigne, Google Threat Analysis Group*
## The Basics
**Disclosure or Patch Date:** 26 March 2021
**Product:** Apple WebKit (Safari)
**Advisory:** https://support.apple.com/en-us/HT212256
**Affected Versions:** 14.4.1 and previous
**First Patched Version:** 14.4.2
**Issue/Bug Report:** https://bugs.webkit.org/show_bug.cgi?id=223561
**Patch CL:**
https://github.com/WebKit/WebKit/commit/629d61f760e57cf322288f528a7fcd318dd14327
**Bug-Introducing CL:**
https://github.com/WebKit/WebKit/commit/5f980f44880269f6e273853961097fcc55cca094
FIXME added in
https://github.com/WebKit/WebKit/commit/9b04ff6bea713b87c903f06b0ac6518bce0d2c4b
**Reporter(s):** Clement Lecigne of Google Threat Analysis Group and Billy
Leonard of Goo
No detection rules found.
No public exploits indexed.
Google Tag
State-backed attackers and commercial surveillance vendors repeatedly use the same exploits
blogs_google_tag·2024-08-29
State-backed attackers and commercial surveillance vendors repeatedly use the same exploits
Threat Analysis Group
## State-backed attackers and commercial surveillance vendors repeatedly use the same exploits
Aug 29, 2024
Today, we’re sharing that Google’s Threat Analysis Group (TAG) observed multiple in-the-wild exploit campaigns, between November 2023 and July 2024, delivered from a watering hole attack on Mongolian government websites. The campaigns first delivered an iOS WebKit exploit affecting iOS versions older than 16.6.1 and then later, a Chrome exploit chain against Android users running versions from m121 to m123. These campaigns delivered n-day exploits for which patches were available, but would still be effective against unpatched devices. We assess with moderate confidence the campaigns are linked to the Russian government-backed actor APT29. In each iteration o
Bleepingcomputer
Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors
blogs_bleepingcomputer·2024-08-29·CVSS 6.1
[MEDIUM] Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors
## Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors
## Bill Toulas
A watering hole is a cyberattack where a legitimate site is compromised with malicious code designed to deliver payloads to visitors that meet specific criteria, like device architecture or location (IP-based).
Interestingly, TAG notes that APT29 used exploits that were almost identical to those used by commercial surveillance-ware vendors like NSO Group and Intellexa, who created and leveraged the flaws as zero days when no fix was available.
## Timeline of attacks
Google's threat analysts note that APT29 has a long history of exploiting zero-day and n-day vulnerabilities.
In 2021, the Russian cyber-operatives exploited CVE-2021-1879 as a zero-day, targeting government officials in Eastern Eu
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “ Apple is aware of a report that this issue may have been actively exploited ,” the company said in security advisories .
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited . Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vul
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “Apple is aware of a report that this issue may have been actively exploited,” the company said in security advisories.
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited. Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vulnera
Qualys
Prevent Pegasus Spyware Attacks with VMDR | Qualys
blogs_qualys·2021-07-23
Prevent Pegasus Spyware Attacks with VMDR | Qualys
#### Table of Contents
- Attack Vectors and Impact of Pegasus Spyware
- VMDR for Mobile Devices Helps Protect from Pegasus Spyware
- Get Started Now
Pegasus spyware is in the news, and it has been used to target devices of critical people from different sectors and countries including journalists, activists, politicians, and business executives. It has been said that a leaked list of 50,000 phone numbers of potential surveillance targets was obtained by Paris-based journalism nonprofit Forbidden Stories and Amnesty International.
Pegasus spyware is a surveillance software created by Israeli cyber intelligence firm NSO Group. Pegasus is one such software developed to gain access to your phone without consent and gather personal and sensitive information and deliver it to the user spying
Qualys
Protect your Devices from Pegasus Spyware using VMDR for Mobile Devices’ Proactive Approach
blogs_qualys·2021-07-23
Protect your Devices from Pegasus Spyware using VMDR for Mobile Devices’ Proactive Approach
## Table of Contents
Attack Vectors and Impact of Pegasus Spyware
VMDR for Mobile Devices Helps Protect from Pegasus Spyware
Get Started Now
Pegasus spyware is in the news, and it has been used to target devices of critical people from different sectors and countries including journalists, activists, politicians, and business executives. It has been said that a leaked list of 50,000 phone numbers of potential surveillance targets was obtained by Paris-based journalism nonprofit Forbidden Stories and Amnesty International.
Pegasus spyware is a surveillance software created by Israeli cyber intelligence firm NSO Group. Pegasus is one such software developed to gain access to your phone without consent and gather personal and sensitive information and deliver it to the user spying on you
Checkpoint
29th March – Threat Intelligence Report
blogs_checkpoint·2021-03-29
CVE-2021-1879 29th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th March, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The official PHP Git server has been compromised in a potential attempt to plant a backdoor in the PHP source code, used by 80% of the websites on the internet. The threat was mitigated within a few hours, and the project migrated to GitHub to better control and prevent similar attacks in the future.
Web shells deployed by t
https://support.apple.com/en-us/HT212256https://support.apple.com/en-us/HT212257https://support.apple.com/en-us/HT212258https://support.apple.com/en-us/HT212256https://support.apple.com/en-us/HT212257https://support.apple.com/en-us/HT212258https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1879
2021-04-02
Published
2021-11-03
Added to CISA KEV
Exploited in the wild