HIGH

CVE-2021-30762

Apple Iphone Os 2021-09-08 CVSS v3.1
CVSS
8.8
KEV

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Summary dbcve.org

Use-after-free vulnerability in WebKit affecting iOS 12.5.4. Processing maliciously crafted web content leads to arbitrary code execution. Actively exploited in the wild as a zero-day.

Mitigation

Apply iOS 12.5.4 security update to affected devices; disable Safari/WEBKIT or restrict web browsing until patch is applied.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

10.99%
Probability of exploitation in next 30 days
95.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE