cbcvebase.
CVE-2021-30661
published 2021-09-08

CVE-2021-30661: A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4…

PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
4.53%
90.5th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Affected

17 ranges
VendorProductVersion rangeFixed in
appleios_14.5_and_ipados
appleios_and_ipados>= unspecified < 14.514.5
appleipados< 14.514.5
appleiphone_os< 12.5.312.5.3
appleiphone_os>= 14.0 < 14.514.5
applemacos>= 11.0 < 11.311.3
applemacos>= unspecified < 11.311.3
applemacos>= unspecified < 12.512.5
applemacos_big_sur
applesafari< 14.114.1
applesafari>= unspecified < 14.114.1
appletvos< 14.514.5
appletvos>= unspecified < 14.514.5
applewatchos< 7.47.4
applewatchos>= unspecified < 7.47.4
debianwebkit2gtk< webkit2gtk 2.30.1-1 (bookworm)webkit2gtk 2.30.1-1 (bookworm)
debianwpewebkit< webkit2gtk 2.30.1-1 (bookworm)webkit2gtk 2.30.1-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in the WebKit Storage component; trigger vector is processing maliciously crafted web content delivered via a specially crafted website
  • Attack vector is remote/web-based: attacker persuades a victim to visit a specially crafted web site to exploit the use-after-free in WebKit
  • Scope of impact extends beyond Apple products — any HTML parser relying on WebKit (including non-Apple products) may be affected
  • Affected Linux packages to hunt for on unpatched systems: webkitgtk (RHEL 6) and webkitgtk3 (RHEL 7); webkit2gtk3 on RHEL 9 is NOT affected
  • Debian/Ubuntu: flag systems running webkit2gtk versions older than 2.30.1-1 across bookworm, bullseye, sid, trixie, and forky
  • ·CVE-2021-30661 is confirmed actively exploited in the wild (CISA KEV listed); treat any unpatched WebKit-based browser or WebKit-dependent application as high-priority
  • ·The vulnerability resides specifically in the WebKit Storage sub-component (use-after-free), not the broader WebKit rendering engine — focus audit/detection on storage-related WebKit code paths
  • ·Fixed versions for Apple platforms: Safari 14.1, iOS/iPadOS 14.5, iOS 12.5.3, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3 — systems below these versions remain vulnerable

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.