CVE-2021-30762
published 2021-09-08CVE-2021-30762: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to…
PriorityP186high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
10.99%
95.4th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < 12.5 | 12.5 |
| apple | iphone_os | < 12.5.4 | 12.5.4 |
| debian | webkit2gtk | < webkit2gtk 2.28.0-2 (bookworm) | webkit2gtk 2.28.0-2 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.28.0-2 (bookworm) | webkit2gtk 2.28.0-2 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector is maliciously crafted web content delivered via a webpage; any WebKit-based browser processing attacker-controlled HTML/JS content is a potential exploitation path. ↗
- →Exploitation requires user interaction — victim must be persuaded to visit a specially crafted website. Monitor for suspicious redirects or drive-by download patterns targeting iOS 12 devices. ↗
- →Scope of impact extends beyond Apple Safari to any non-Apple product relying on WebKit for HTML parsing. Broaden detection coverage to all WebKit-based HTML processors. ↗
- →Vulnerability is confirmed actively exploited in the wild (CISA KEV listed). Prioritize detection and patching for iOS devices running versions prior to iOS 12.5.4. ↗
- ·Red Hat Enterprise Linux 6 (webkitgtk) and RHEL 7 (webkitgtk3) are marked 'Will not fix', meaning vulnerable versions remain in those environments indefinitely. Detection should account for these persistently unpatched deployments. ↗
- ·RHEL 9 (webkit2gtk3) is assessed as 'Not affected', so detection efforts on that platform for this specific CVE can be deprioritized. ↗
- ·Debian-based systems are resolved at webkit2gtk version 2.28.0-2 across all active releases (bookworm, bullseye, sid, trixie, forky). Systems below this version remain vulnerable. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS WebKit Use-After-Free Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2021-30762 [HIGH] CWE-416 Apple iOS WebKit Use-After-Free Vulnerability
Vulnerability: Apple iOS WebKit Use-After-Free Vulnerability
Affected: Apple iOS
Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-30762
Remediation Due Date: 2021-11-17
Red Hat
webkitgtk: Use-after-free leading to arbitrary code execution
vendor_redhat·2021-07-28·CVSS 8.8
CVE-2021-30762 [HIGH] CWE-20 webkitgtk: Use-after-free leading to arbitrary code execution
webkitgtk: Use-after-free leading to arbitrary code execution
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
A flaw was found in the webkitgtk package. Affected versions of this package could allow a remote attacker to execute arbitrary code on the system caused by a use-after-free in the WebKit component. By persuading a victim to visit a specially crafted Web site, an attacker can execute arbitrary code on the system.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Package: webkit2gtk3 (Red H
Apple
CVE-2021-30762: iOS 12.5.4
vendor_apple·2021-06-14·CVSS 8.8
CVE-2021-30762 [HIGH] CVE-2021-30762: iOS 12.5.4
Apple Security Update: About the security content of iOS 12.5.4
Product: iOS
Version: 12.5.4
CVE: CVE-2021-30762
Component: WebKit
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A use after free issue was addressed with improved memory management.
Debian
CVE-2021-30762: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
vendor_debian·2021·CVSS 8.8
CVE-2021-30762 [HIGH] CVE-2021-30762: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Scope: local
bookworm: resolved (fixed in 2.28.0-2)
bullseye: resolved (fixed in 2.28.0-2)
forky: resolved (fixed in 2.28.0-2)
sid: resolved (fixed in 2.28.0-2)
trixie: resolved (fixed in 2.28.0-2)
GHSA
GHSA-gj4g-95xx-7pc7: A use after free issue was addressed with improved memory management
ghsa_unreviewed·2022-05-24
CVE-2021-30762 [HIGH] CWE-416 GHSA-gj4g-95xx-7pc7: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
OSV
CVE-2021-30762: A use after free issue was addressed with improved memory management
osv·2021-09-08·CVSS 8.8
CVE-2021-30762 [HIGH] CVE-2021-30762: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
VulnCheck
Apple iOS WebKit Use-After-Free Vulnerability
vulncheck·2021·CVSS 8.8
CVE-2021-30762 [HIGH] CWE-416 Apple iOS WebKit Use-After-Free Vulnerability
Apple iOS WebKit Use-After-Free Vulnerability
Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple iOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://support.apple.com/kb/HT212548; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2021-11-17
No detection rules found.
No public exploits indexed.
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “ Apple is aware of a report that this issue may have been actively exploited ,” the company said in security advisories .
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited . Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vul
Qualys
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-10-18·CVSS 7.0
[HIGH] Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices | Qualys
Apple recently released iOS and iPadOS 15.0.2 as an emergency security update that addresses 1 critical zero-day vulnerabilities, which is exploited in wild. Qualys recommends that security teams should immediately update all devices running iOS and iPadOS to the latest version. “Apple is aware of a report that this issue may have been actively exploited,” the company said in security advisories.
This year, Apple has released multiple emergency releases to fix the actively exploited vulnerabilities which Apple is aware of a report that this issue may have been actively exploited. Successful exploitation of the vulnerability allows an application to execute arbitrary code with kernel privileges, and spyware like Pegasus can be easily deployed on affect devices, and exploiting other vulnera
Checkpoint
21st June – Threat Intelligence Report
blogs_checkpoint·2021-06-21
CVE-2021-30554 21st June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
South Korea’s Korea Atomic Energy Research Institute (KAERI) disclosed a breach in their internal network caused by a VPN vulnerability. The state-run nuclear institute’s network was attacked last month by what appears to be a North Korean threat actor.
Researchers have identified LastConn, a malware distributed by TA402 also
2021-09-08
Published
2021-11-03
Added to CISA KEV
Exploited in the wild