LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30661: Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30661 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This…

CVE-2021-30661 is a use-after-free vulnerability in WebKit Storage affecting Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari. Processing maliciously crafted web content can lead to code execution. The issue can also affect other HTML parsers that rely on WebKit, not only Apple Safari. For defenders this matters because web content is routinely rendered on endpoints and in embedded browsers, giving an attacker a path to run code if a vulnerable WebKit build is present. Confirm exact product scope and fixes against the vendor advisory.

How it works

The weakness is CWE-416 (use-after-free). In this class of flaw, memory is freed while a pointer to it is still used. When WebKit Storage processes specially crafted web content, that dangling reference can be abused so that subsequent operations act on memory the attacker influences. The CISA summary states the result is code execution. Public detail beyond that class behavior is limited; do not assume specific heap layouts, gadgets, or exploit chains without vendor or trusted technical analysis. Any HTML parser or browser component that embeds the affected WebKit Storage logic may be in scope, including non-Apple products that depend on WebKit for HTML processing.

Am I affected? How to find it in your systems

WebKit appears on Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch) and in Safari, and may appear in third-party applications or appliances that bundle WebKit for rendering or HTML parsing. Inventory steps:

If version or configuration detail is unclear, treat the system as potentially affected until you verify against the vendor advisory.

How to remediate

Patch first. Apply the updates Apple (and any other vendor shipping the affected WebKit) published for this vulnerability, following the vendor instructions referenced in the CISA required action. Prioritize internet-facing and high-exposure browsing fleets, then remaining Apple devices and any non-Apple products that embed WebKit.

If you can't patch immediately

Use compensating controls until updates are installed:

These measures reduce risk; they do not replace the vendor update.

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to device compromise and data theft even when ransomware use is not documented for this CVE. If you suspect exposure, follow your incident response process: isolate affected systems, preserve logs, credential-reset where appropriate, and assess what data the compromised context could access. You can run a free exposure scan of your email addresses against known breach data to see whether those identities already appear in public breach corpora and prioritize further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-416
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities