HIGH

CVE-2021-30663

Apple Safari 2021-09-08 CVSS v3.1
CVSS
8.8
KEV

Description

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.

Summary dbcve.org

Integer overflow in WebKit allows processing of maliciously crafted web content to trigger the overflow, leading to arbitrary code execution with the privileges of the Safari/WebKit process. The vulnerability was addressed through improved input validation.

Mitigation

Apply vendor-supplied updates: iOS 14.5.1+, iPadOS 14.5.1+, tvOS 14.6+, iOS 12.5.3+, Safari 14.1.1+, or macOS Big Sur 11.3.1+. As an interim measure, disable JavaScript in Safari or restrict web browsing to trusted sites only.

Weakness (CWE)

CWE-190 Integer Overflow

EPSS Score

3.49%
Probability of exploitation in next 30 days
88.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE