CVE-2021-30761
Description
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Summary dbcve.org
A memory corruption vulnerability in WebKit (the browser engine used by Safari and iOS) that could be triggered by processing maliciously crafted web content, potentially leading to arbitrary code execution. The fix involved improved state management, suggesting a use-after-free or similar memory management flaw. This was actively exploited as a zero-day.
Mitigation
Apply iOS 12.5.4 security update or upgrade to a supported iOS version to remediate. For organizations, deploy via MDM or direct update to all affected iOS 12 devices.