cbcvebase.
CVE-2021-30858
published 2021-08-24

CVE-2021-30858: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing…

PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
13.49%
96.0th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < 14.814.8
appleios_14.8_and_ipados
appleipados>= 13.1 < 14.814.8
appleiphone_os< 12.5.512.5.5
appleiphone_os>= 13.0 < 14.814.8
applemacos< 11.611.6
applemacos>= unspecified < 11.611.6
applemacos_big_sur
applesafari
debiandebian_linux
debiandebian_linux
debianwebkit2gtk< webkit2gtk 2.32.4-1 (bookworm)webkit2gtk 2.32.4-1 (bookworm)
debianwpewebkit< webkit2gtk 2.32.4-1 (bookworm)webkit2gtk 2.32.4-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2021-30858 is a WebKit use-after-free triggered by processing a specially crafted web page; detection should focus on WebKit/WebKitGTK versions below the fixed releases (webkit2gtk 2.32.4-1 on Debian/Ubuntu)
  • The vulnerability is exploitable via a maliciously crafted web page (zero-click or one-click browser vector); monitor for suspicious WebKit/browser process crashes or unexpected code execution originating from web content rendering processes
  • This vulnerability was actively exploited in the wild as part of the NSO Pegasus spyware campaign; treat any unpatched iOS/iPadOS/macOS device as potentially compromised
  • On Ubuntu/Debian Linux systems, check for WebKitGTK versions older than 2.32.4-1; applications using WebKitGTK (e.g., Epiphany) are attack surface
  • Qualys QID 610367 (signature version SEM VULNSIGS-1.0.0.45) detects CVE-2021-30858 on iOS/iPadOS 14.x devices; use this QID for asset-level confirmation of exposure
  • ·The vulnerability affects a broad range of Apple devices; patched versions are iOS/iPadOS 14.8, macOS Big Sur 11.6, iOS/iPadOS 12.5.5 (for older devices), and WebKitGTK 2.32.4-1 on Linux — ensure detection logic accounts for all affected platforms
  • ·On older Apple hardware (iPhone 5s, iPhone 6/6 Plus, iPad Air, iPad mini 2/3, iPod touch 6th gen), the fix was delivered separately in iOS/iPadOS 12.5.5 — detection tools must check for this separate patch train

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.