HIGH
CVE-2021-30663
CVSS
8.8
KEV
Description
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Summary dbcve.org
Integer overflow in WebKit allows processing of maliciously crafted web content to trigger the overflow, leading to arbitrary code execution with the privileges of the Safari/WebKit process. The vulnerability was addressed through improved input validation.
Mitigation
Apply vendor-supplied updates: iOS 14.5.1+, iPadOS 14.5.1+, tvOS 14.6+, iOS 12.5.3+, Safari 14.1.1+, or macOS Big Sur 11.3.1+. As an interim measure, disable JavaScript in Safari or restrict web browsing to trusted sites only.
Weakness (CWE)
CWE-190
Integer Overflow
EPSS Score
3.49%
Probability of exploitation in next 30 days
88.7th percentile
References
https://support.apple.com/en-us/HT212335
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT212336
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT212341
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT212532
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT212534
Release Notes, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30663
Third Party Advisory, US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.