cbcvebase.
CVE-2021-30762
published 2021-09-08

CVE-2021-30762: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to…

PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
10.99%
95.4th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Affected

5 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < 12.512.5
appleiphone_os< 12.5.412.5.4
debianwebkit2gtk< webkit2gtk 2.28.0-2 (bookworm)webkit2gtk 2.28.0-2 (bookworm)
debianwpewebkit< webkit2gtk 2.28.0-2 (bookworm)webkit2gtk 2.28.0-2 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger vector is maliciously crafted web content delivered via a webpage; any WebKit-based browser processing attacker-controlled HTML/JS content is a potential exploitation path.
  • Exploitation requires user interaction — victim must be persuaded to visit a specially crafted website. Monitor for suspicious redirects or drive-by download patterns targeting iOS 12 devices.
  • Scope of impact extends beyond Apple Safari to any non-Apple product relying on WebKit for HTML parsing. Broaden detection coverage to all WebKit-based HTML processors.
  • Vulnerability is confirmed actively exploited in the wild (CISA KEV listed). Prioritize detection and patching for iOS devices running versions prior to iOS 12.5.4.
  • ·Red Hat Enterprise Linux 6 (webkitgtk) and RHEL 7 (webkitgtk3) are marked 'Will not fix', meaning vulnerable versions remain in those environments indefinitely. Detection should account for these persistently unpatched deployments.
  • ·RHEL 9 (webkit2gtk3) is assessed as 'Not affected', so detection efforts on that platform for this specific CVE can be deprioritized.
  • ·Debian-based systems are resolved at webkit2gtk version 2.28.0-2 across all active releases (bookworm, bullseye, sid, trixie, forky). Systems below this version remain vulnerable.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.