cbcvebase.
CVE-2021-30663
published 2021-09-08

CVE-2021-30663: An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1…

PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
3.69%
88.5th percentile
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.

Affected

15 ranges
VendorProductVersion rangeFixed in
appleipados>= 14.0 < 14.5.114.5.1
appleiphone_os< 12.5.312.5.3
appleiphone_os>= 14.0 < 14.5.114.5.1
applemacos>= 11.0 < 11.3.111.3.1
applemacos>= unspecified < 11.311.3
applemacos>= unspecified < 14.514.5
applemacos>= unspecified < 12.512.5
applemacos>= unspecified < 14.614.6
applemacos>= unspecified < 14.114.1
applesafari< 14.1.114.1.1
applesafari
appletvos< 14.614.6
appletvos
debianwebkit2gtk< webkit2gtk 2.32.3-1 (bookworm)webkit2gtk 2.32.3-1 (bookworm)
debianwpewebkit< webkit2gtk 2.32.3-1 (bookworm)webkit2gtk 2.32.3-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in the WebKit component; any processing of maliciously crafted web content via WebKit-based browsers/parsers (Apple Safari, WebKitGTK, and non-Apple products relying on WebKit for HTML processing) can trigger the integer overflow leading to arbitrary code execution.
  • CVE-2021-30663 has been confirmed as actively exploited in the wild by Apple; prioritize detection and patching on all WebKit-based products.
  • The vulnerability is an integer overflow in WebKit triggered by processing maliciously crafted web content; monitor for unexpected code execution originating from WebKit-based browser processes (e.g., Safari, WebKitGTK renderer processes).
  • On Linux/Debian systems, flag unpatched WebKitGTK installations below version 2.32.3-1 as vulnerable to this CVE.
  • On Red Hat systems, webkitgtk (RHEL 6) and webkitgtk3 (RHEL 7) are affected; an attacker can exploit this by persuading a victim to visit a specially crafted website — monitor for suspicious web browsing activity from these packages.
  • ·webkit2gtk3 on Red Hat Enterprise Linux 9 is NOT affected by this CVE; avoid false-positive alerting on RHEL 9 systems running webkit2gtk3.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.