cbcvebase.
CVE-2021-30761
published 2021-09-08

CVE-2021-30761: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead…

PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
10.59%
95.3th percentile
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Affected

5 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < 12.512.5
appleiphone_os< 12.5.412.5.4
debianwebkit2gtk< webkit2gtk 2.26.1-2 (bookworm)webkit2gtk 2.26.1-2 (bookworm)
debianwpewebkit< webkit2gtk 2.26.1-2 (bookworm)webkit2gtk 2.26.1-2 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger vector is maliciously crafted web content processed by WebKit; monitor for suspicious web content delivery targeting WebKit-based browsers (Apple Safari and other WebKit-dependent HTML parsers)
  • Vulnerability resides in the WebKit component; focus detection on WebKit-based processes (e.g., WebContent process on iOS/macOS) exhibiting memory corruption indicators such as unexpected crashes or code execution anomalies
  • Non-Apple products relying on WebKit for HTML processing are also in scope; broaden detection to include any WebKit-based HTML parser, not just Apple Safari
  • ·Vulnerability is confirmed actively exploited in the wild per Apple and CISA KEV; prioritize patching iOS devices still running versions prior to iOS 12.5.4
  • ·Red Hat Enterprise Linux 9 (webkit2gtk3) is listed as Not Affected; RHEL 6 (webkitgtk) and RHEL 7 (webkitgtk3) are listed as Affected — scope detection and patching efforts accordingly
  • ·Debian resolved this vulnerability in webkit2gtk version 2.26.1-2 across all tracked branches (bookworm, bullseye, forky, sid, trixie)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.