LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-30858: Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-30858 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers…

CVE-2021-30858 is a use-after-free vulnerability in WebKit on Apple iOS, iPadOS, and macOS. Processing maliciously crafted web content can lead to code execution. It matters because WebKit underpins Safari and other HTML parsers, so a successful exploit can compromise devices that render untrusted web content. Confirm exact scope and fixed builds against the vendor advisory.

CISA notes that the issue can affect HTML parsers that use WebKit, including Apple Safari and non-Apple products that rely on WebKit for HTML processing. Known ransomware use is not documented. The required action is to apply updates per vendor instructions.

How it works

The weakness is CWE-416 (use-after-free). In this class of flaw, memory is freed while a pointer to it remains in use. If an attacker can influence what is written into that freed region and then trigger a later use of the stale pointer, the program may execute attacker-controlled data.

For this CVE, the CISA summary states that Apple iOS, iPadOS, and macOS WebKit contain a use-after-free that leads to code execution when processing maliciously crafted web content. An attacker would typically deliver that content through a web page or other HTML that is parsed by a WebKit-based engine. Specific exploit mechanics, version ranges, and any privilege or sandbox details must be confirmed against the vendor advisory; do not assume unstated behavior.

Am I affected? How to find it in your systems

This software runs on Apple mobile and desktop platforms: iOS and iPadOS devices, and macOS systems. WebKit is used by Safari and can appear in other applications or embedded HTML parsers that depend on WebKit, including some non-Apple products.

How to remediate

Patch first. Apply the updates Apple provides for iOS, iPadOS, and macOS per the vendor advisory and CISA’s direction to apply updates per vendor instructions. Prioritize internet-facing and user-browsing devices.

If you can't patch immediately

Reduce exposure until updates can be applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and data theft even when ransomware use is not documented for this CVE. If you suspect exposure, isolate affected devices, preserve logs, rotate credentials accessible from those devices, and follow your incident response process. You can run a free exposure scan of your email to check known breach data and determine whether addresses tied to your environment appear in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS, iPadOS, and macOS
WeaknessCWE-416
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities