LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30665: Apple Multiple Products WebKit Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30665 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could…

CVE-2021-30665 is a memory corruption vulnerability in WebKit affecting multiple Apple products, including iOS, iPadOS, macOS, watchOS, and tvOS. When WebKit processes maliciously crafted web content, the flaw can lead to code execution. It can also affect other HTML parsers that rely on WebKit, such as Apple Safari and non-Apple products that use the same engine for HTML processing.

For IT and security teams, this matters because web content is routinely rendered on endpoints and in browsers across the estate. Successful abuse can give an attacker a path to run code in the context of the affected process. Confirm exact product coverage and fixed builds against the vendor advisory before declaring systems clear.

How it works

The weakness is classified as CWE-787, an out-of-bounds write style of memory corruption. In practical terms, WebKit mishandles certain crafted web content so that memory is written outside the intended bounds. That corruption can be leveraged to achieve code execution when the content is processed.

An attacker would typically deliver the malicious content through normal web channels—pages, embedded resources, or other content that causes the vulnerable WebKit component to parse it. No further exploit mechanics are specified in the available record; treat any public proof-of-concept claims with caution and validate behavior only in controlled lab conditions against vendor guidance. The impact extends beyond Safari to any HTML processing path that embeds the affected WebKit.

Am I affected? How to find it in your systems

WebKit ships as part of Apple’s operating systems and is used by Safari and by other applications that render HTML via the system WebKit. Non-Apple products that bundle or link WebKit for HTML parsing may also be in scope; inventory those separately and confirm with their vendors.

How to remediate

Patch first. Apply the updates Apple provides for the affected products, following the vendor instructions referenced in the CISA required action. Use your standard OS and application update channels (MDM, software update, managed app deployment) and verify installation across the fleet.

If you can't patch immediately

Until updates are deployed, reduce exposure with compensating controls while you schedule the official fix.

These steps lower risk; they do not replace the vendor update.

If your data may have been exposed

Actively exploited memory-corruption flaws in web engines can lead to device compromise and follow-on data access. Ransomware use is not documented for this CVE in the available facts. If you suspect compromise, isolate affected devices, preserve logs and disk images, rotate credentials reachable from those systems, and follow your incident response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior dumps while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities