CVE-2021-30666
Description
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Summary dbcve.org
Buffer overflow vulnerability in WebKit (iOS Safari browser engine) that allows arbitrary code execution when processing maliciously crafted web content. This zero-day vulnerability affects iOS 12.5.3 and earlier versions and was actively exploited in the wild.
Mitigation
Apply iOS 12.5.3 security update immediately to affected devices. For devices that cannot receive this update, implement compensating controls such as restricting Safari usage or deploying mobile device management (MDM) policies to block access to untrusted web content.