VDB
CVE-2021-30869
CVE-2021-30869
PUBLISHED
KEV
CVSS 8.800000190734863 HIGH
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
EPSS 1.72% · 82.7th percentile
Risk Scores
CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
1.72%
82.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | macOS | unspecified |
| Apple | iOS | unspecified |
Timeline
- Aug 24, 2021 CVE Published
- Sep 13, 2021 PoC Published
- Sep 14, 2021 PoC Published
- Sep 23, 2021 PoC Published
- Sep 24, 2021 PoC Published
- Oct 20, 2021 EPSS Score
- Oct 21, 2021 EPSS Score
- Nov 3, 2021 CISA KEV Added
- Nov 8, 2021 PoC Published
- Nov 20, 2021 PoC Published
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
References
- https://support.apple.com/fr-fr/HT212825 advisory
- https://support.apple.com/fr-fr/HT212824 advisory
- https://support.apple.com/en-us/HT212804 url
- https://support.apple.com/en-us/HT212807 url
- 20210917 APPLE-SA-2021-09-13-3 macOS Big Sur 11.6 mailing-list
- 20210917 APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8 mailing-list
- 20210917 APPLE-SA-2021-09-13-5 Safari 14.1.2 mailing-list
- [oss-security] 20210920 WebKitGTK and WPE WebKit Security Advisory WSA-2021-0005 mailing-list
- FEDORA-2021-c00e45b6c0 vendor-advisory
- 20210921 APPLE-SA-2021-09-20-6 Additional information for APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8 mailing-list
- 20210921 APPLE-SA-2021-09-20-7 Additional information for APPLE-SA-2021-09-13-3 macOS Big Sur 11.6 mailing-list
- DSA-4975 vendor-advisory
- DSA-4976 vendor-advisory
- https://support.apple.com/kb/HT212824 url
- 20210924 APPLE-SA-2021-09-23-1 iOS 12.5.5 mailing-list
- FEDORA-2021-edf6957b7d vendor-advisory
- [oss-security] 20211026 WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 mailing-list
- [oss-security] 20211027 Re: WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 mailing-list
- [oss-security] 20211027 Re: WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 mailing-list
- [oss-security] 20211027 Re: WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 mailing-list
…and 1 more