CVE-2021-30761
published 2021-09-08CVE-2021-30761: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead…
PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
10.59%
95.3th percentile
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < 12.5 | 12.5 |
| apple | iphone_os | < 12.5.4 | 12.5.4 |
| debian | webkit2gtk | < webkit2gtk 2.26.1-2 (bookworm) | webkit2gtk 2.26.1-2 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.26.1-2 (bookworm) | webkit2gtk 2.26.1-2 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector is maliciously crafted web content processed by WebKit; monitor for suspicious web content delivery targeting WebKit-based browsers (Apple Safari and other WebKit-dependent HTML parsers) ↗
- →Vulnerability resides in the WebKit component; focus detection on WebKit-based processes (e.g., WebContent process on iOS/macOS) exhibiting memory corruption indicators such as unexpected crashes or code execution anomalies ↗
- →Non-Apple products relying on WebKit for HTML processing are also in scope; broaden detection to include any WebKit-based HTML parser, not just Apple Safari ↗
- ·Vulnerability is confirmed actively exploited in the wild per Apple and CISA KEV; prioritize patching iOS devices still running versions prior to iOS 12.5.4 ↗
- ·Red Hat Enterprise Linux 9 (webkit2gtk3) is listed as Not Affected; RHEL 6 (webkitgtk) and RHEL 7 (webkitgtk3) are listed as Affected — scope detection and patching efforts accordingly ↗
- ·Debian resolved this vulnerability in webkit2gtk version 2.26.1-2 across all tracked branches (bookworm, bullseye, forky, sid, trixie) ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6qp6-2ggr-xv6x: A memory corruption issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2021-30761 [HIGH] CWE-787 GHSA-6qp6-2ggr-xv6x: A memory corruption issue was addressed with improved state management
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
OSV
CVE-2021-30761: A memory corruption issue was addressed with improved state management
osv·2021-09-08·CVSS 8.8
CVE-2021-30761 [HIGH] CVE-2021-30761: A memory corruption issue was addressed with improved state management
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
VulnCheck
Apple iOS WebKit Memory Corruption Vulnerability
vulncheck·2021·CVSS 8.8
CVE-2021-30761 [HIGH] CWE-787 Apple iOS WebKit Memory Corruption Vulnerability
Apple iOS WebKit Memory Corruption Vulnerability
Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple iOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://support.apple.com/kb/HT212548; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2021-11-17
CISA
Apple iOS WebKit Memory Corruption Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2021-30761 [HIGH] CWE-787 Apple iOS WebKit Memory Corruption Vulnerability
Vulnerability: Apple iOS WebKit Memory Corruption Vulnerability
Affected: Apple iOS
Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30761
Remediation Due Date: 2021-11-17
Red Hat
webkitgtk: Memory corruption leading to arbitrary code execution
vendor_redhat·2021-07-28·CVSS 8.8
CVE-2021-30761 [HIGH] CWE-20 webkitgtk: Memory corruption leading to arbitrary code execution
webkitgtk: Memory corruption leading to arbitrary code execution
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
A flaw was found in the webkitgtk package. Affected versions of this package could allow a remote attacker to execute arbitrary code on the system caused by memory corruption in the WebKit component. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Affected
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Affecte
Apple
CVE-2021-30761: iOS 12.5.4
vendor_apple·2021-06-14·CVSS 8.8
CVE-2021-30761 [HIGH] CVE-2021-30761: iOS 12.5.4
Apple Security Update: About the security content of iOS 12.5.4
Product: iOS
Version: 12.5.4
CVE: CVE-2021-30761
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A memory corruption issue was addressed with improved state management.
Debian
CVE-2021-30761: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
vendor_debian·2021·CVSS 8.8
CVE-2021-30761 [HIGH] CVE-2021-30761: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Scope: local
bookworm: resolved (fixed in 2.26.1-2)
bullseye: resolved (fixed in 2.26.1-2)
forky: resolved (fixed in 2.26.1-2)
sid: resolved (fixed in 2.26.1-2)
trixie: resolved (fixed in 2.26.1-2)
No detection rules found.
No public exploits indexed.
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “ Apple is aware of a report that this issue may have been actively exploited ,” the company said in security advisories .
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited . Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vul
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “Apple is aware of a report that this issue may have been actively exploited,” the company said in security advisories.
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited. Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vulnera
Checkpoint
21st June – Threat Intelligence Report
blogs_checkpoint·2021-06-21
CVE-2021-30554 21st June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
South Korea’s Korea Atomic Energy Research Institute (KAERI) disclosed a breach in their internal network caused by a VPN vulnerability. The state-run nuclear institute’s network was attacked last month by what appears to be a North Korean threat actor.
Researchers have identified LastConn, a malware distributed by TA402 also
2021-09-08
Published
2021-11-03
Added to CISA KEV
Exploited in the wild