CVE-2021-30666
published 2021-09-08CVE-2021-30666: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to…
PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
3.03%
86.0th percentile
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < 12.5 | 12.5 |
| apple | iphone_os | < 12.5.3 | 12.5.3 |
| debian | webkit2gtk | < webkit2gtk 2.26.1-2 (bookworm) | webkit2gtk 2.26.1-2 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.26.1-2 (bookworm) | webkit2gtk 2.26.1-2 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector is processing maliciously crafted web content via WebKit; monitor for suspicious web content rendering activity in WebKit-based browsers (Apple Safari and non-Apple WebKit-based products) ↗
- →Affected packages on Red Hat Enterprise Linux: webkitgtk (RHEL 6) and webkitgtk3 (RHEL 7) — monitor these packages for exploitation attempts or unexpected crashes ↗
- →Attack vector is social engineering / drive-by: attacker persuades victim to visit a specially crafted website to trigger the buffer overflow; monitor for unusual browser crashes or code execution following web browsing ↗
- →This vulnerability could impact HTML parsers that use WebKit broadly, not just Apple Safari — extend detection scope to any non-Apple product relying on WebKit for HTML processing ↗
- ·Vulnerability is confirmed actively exploited in the wild (CISA KEV listed); patched in iOS 12.5.3 and Debian webkit2gtk 2.26.1-2; webkit2gtk3 on RHEL 9 is not affected ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS WebKit Buffer Overflow Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2021-30666 [HIGH] CWE-119 Apple iOS WebKit Buffer Overflow Vulnerability
Vulnerability: Apple iOS WebKit Buffer Overflow Vulnerability
Affected: Apple iOS
Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30666
Remediation Due Date: 2021-11-17
Red Hat
webkitgtk: Buffer overflow leading to arbitrary code execution
vendor_redhat·2021-07-28·CVSS 8.8
CVE-2021-30666 [HIGH] CWE-20 webkitgtk: Buffer overflow leading to arbitrary code execution
webkitgtk: Buffer overflow leading to arbitrary code execution
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
A flaw was found in the webkitgtk package. Affected versions of this package are vulnerable to a buffer overflow caused by improper bounds checking by the WebKit component. By persuading a victim to visit a specially crafted Web site, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Affected
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Affecte
Debian
CVE-2021-30666: webkit2gtk - A buffer overflow issue was addressed with improved memory handling. This issue ...
vendor_debian·2021·CVSS 8.8
CVE-2021-30666 [HIGH] CVE-2021-30666: webkit2gtk - A buffer overflow issue was addressed with improved memory handling. This issue ...
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Scope: local
bookworm: resolved (fixed in 2.26.1-2)
bullseye: resolved (fixed in 2.26.1-2)
forky: resolved (fixed in 2.26.1-2)
sid: resolved (fixed in 2.26.1-2)
trixie: resolved (fixed in 2.26.1-2)
GHSA
GHSA-4cx8-frpf-fjc3: A buffer overflow issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2021-30666 [HIGH] CWE-119 GHSA-4cx8-frpf-fjc3: A buffer overflow issue was addressed with improved memory handling
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
OSV
CVE-2021-30666: A buffer overflow issue was addressed with improved memory handling
osv·2021-09-08·CVSS 8.8
CVE-2021-30666 [HIGH] CVE-2021-30666: A buffer overflow issue was addressed with improved memory handling
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
VulnCheck
Apple iOS WebKit Buffer Overflow Vulnerability
vulncheck·2021·CVSS 8.8
CVE-2021-30666 [HIGH] CWE-119 Apple iOS WebKit Buffer Overflow Vulnerability
Apple iOS WebKit Buffer Overflow Vulnerability
Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple iOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://support.apple.com/kb/HT212341; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2021-11-17
No detection rules found.
No public exploits indexed.
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “ Apple is aware of a report that this issue may have been actively exploited ,” the company said in security advisories .
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited . Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vul
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “Apple is aware of a report that this issue may have been actively exploited,” the company said in security advisories.
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited. Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vulnera
Qualys
Prevent Pegasus Spyware Attacks with VMDR | Qualys
blogs_qualys·2021-07-23
Prevent Pegasus Spyware Attacks with VMDR | Qualys
#### Table of Contents
- Attack Vectors and Impact of Pegasus Spyware
- VMDR for Mobile Devices Helps Protect from Pegasus Spyware
- Get Started Now
Pegasus spyware is in the news, and it has been used to target devices of critical people from different sectors and countries including journalists, activists, politicians, and business executives. It has been said that a leaked list of 50,000 phone numbers of potential surveillance targets was obtained by Paris-based journalism nonprofit Forbidden Stories and Amnesty International.
Pegasus spyware is a surveillance software created by Israeli cyber intelligence firm NSO Group. Pegasus is one such software developed to gain access to your phone without consent and gather personal and sensitive information and deliver it to the user spying
Qualys
Protect your Devices from Pegasus Spyware using VMDR for Mobile Devices’ Proactive Approach
blogs_qualys·2021-07-23
Protect your Devices from Pegasus Spyware using VMDR for Mobile Devices’ Proactive Approach
## Table of Contents
Attack Vectors and Impact of Pegasus Spyware
VMDR for Mobile Devices Helps Protect from Pegasus Spyware
Get Started Now
Pegasus spyware is in the news, and it has been used to target devices of critical people from different sectors and countries including journalists, activists, politicians, and business executives. It has been said that a leaked list of 50,000 phone numbers of potential surveillance targets was obtained by Paris-based journalism nonprofit Forbidden Stories and Amnesty International.
Pegasus spyware is a surveillance software created by Israeli cyber intelligence firm NSO Group. Pegasus is one such software developed to gain access to your phone without consent and gather personal and sensitive information and deliver it to the user spying on you
2021-09-08
Published
2021-11-03
Added to CISA KEV
Exploited in the wild