HIGH

CVE-2021-30761

Apple Iphone Os 2021-09-08 CVSS v3.1
CVSS
8.8
KEV

Description

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Summary dbcve.org

A memory corruption vulnerability in WebKit (the browser engine used by Safari and iOS) that could be triggered by processing maliciously crafted web content, potentially leading to arbitrary code execution. The fix involved improved state management, suggesting a use-after-free or similar memory management flaw. This was actively exploited as a zero-day.

Mitigation

Apply iOS 12.5.4 security update or upgrade to a supported iOS version to remediate. For organizations, deploy via MDM or direct update to all affected iOS 12 devices.

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

10.55%
Probability of exploitation in next 30 days
95.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE