LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30761: Apple iOS WebKit Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30761 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit…

CVE-2021-30761 is a memory corruption vulnerability in Apple iOS WebKit that can lead to code execution when the component processes maliciously crafted web content. It matters because WebKit underpins browsing and HTML parsing on iOS and can also appear in other products that embed WebKit, so a successful exploit may give an attacker a foothold on the device or in any dependent HTML-processing path.

CISA notes that the issue can affect HTML parsers that use WebKit, including Apple Safari and non-Apple products that rely on WebKit. Defenders should treat any unpatched WebKit-based surface as in scope until they confirm status against the vendor advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write), a form of memory corruption. In broad terms, the vulnerable code mishandles memory while parsing or rendering web content. An attacker who can present specially crafted web content to the affected WebKit instance may trigger the corruption and achieve code execution in the context of the process that hosts WebKit.

No further exploit mechanics are provided in the available facts. Exact trigger conditions, required user interaction, and any sandbox escape details must be confirmed against the vendor advisory. The practical takeaway for defenders is that the attack surface is content processing: any path that feeds untrusted HTML or web content into WebKit is relevant.

Am I affected? How to find it in your systems

The vulnerability is reported against Apple iOS WebKit. WebKit typically runs inside the Safari browser and other system components that render web content on iOS devices. It can also appear in third-party applications or non-Apple products that embed WebKit for HTML parsing.

Because public detail on exact affected builds is limited here, confirm every version and configuration against the official vendor advisory before declaring a system clear.

How to remediate

Patch first. Apply the updates Apple released for this issue, following the vendor’s instructions exactly as CISA requires. Use your MDM or standard iOS update process to drive the fixed build to all managed devices, and verify installation afterward.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps do not eliminate the vulnerability; they only buy time until the official update is installed.

If your data may have been exposed

Actively exploited memory-corruption bugs in content parsers can lead to device compromise and subsequent data exposure. Known ransomware use of this specific CVE is not documented in the provided facts, but any confirmed compromise should still trigger standard incident response: isolate the device, preserve logs, rotate credentials accessible from it, and assess what data the device could reach. You can run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts already appear in public breach corpora, then proceed with password resets and monitoring as needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities