HIGH

CVE-2021-30666

Apple Iphone Os 2021-09-08 CVSS v3.1
CVSS
8.8
KEV

Description

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Summary dbcve.org

Buffer overflow vulnerability in WebKit (iOS Safari browser engine) that allows arbitrary code execution when processing maliciously crafted web content. This zero-day vulnerability affects iOS 12.5.3 and earlier versions and was actively exploited in the wild.

Mitigation

Apply iOS 12.5.3 security update immediately to affected devices. For devices that cannot receive this update, implement compensating controls such as restricting Safari usage or deploying mobile device management (MDM) policies to block access to untrusted web content.

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error

EPSS Score

3%
Probability of exploitation in next 30 days
86.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE