cbcvebase.
CVE-2021-30666
published 2021-09-08

CVE-2021-30666: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to…

PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
3.03%
86.0th percentile
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Affected

4 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < 12.512.5
appleiphone_os< 12.5.312.5.3
debianwebkit2gtk< webkit2gtk 2.26.1-2 (bookworm)webkit2gtk 2.26.1-2 (bookworm)
debianwpewebkit< webkit2gtk 2.26.1-2 (bookworm)webkit2gtk 2.26.1-2 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger vector is processing maliciously crafted web content via WebKit; monitor for suspicious web content rendering activity in WebKit-based browsers (Apple Safari and non-Apple WebKit-based products)
  • Affected packages on Red Hat Enterprise Linux: webkitgtk (RHEL 6) and webkitgtk3 (RHEL 7) — monitor these packages for exploitation attempts or unexpected crashes
  • Attack vector is social engineering / drive-by: attacker persuades victim to visit a specially crafted website to trigger the buffer overflow; monitor for unusual browser crashes or code execution following web browsing
  • This vulnerability could impact HTML parsers that use WebKit broadly, not just Apple Safari — extend detection scope to any non-Apple product relying on WebKit for HTML processing
  • ·Vulnerability is confirmed actively exploited in the wild (CISA KEV listed); patched in iOS 12.5.3 and Debian webkit2gtk 2.26.1-2; webkit2gtk3 on RHEL 9 is not affected

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.