Skip to content
COOEY

EXPOSURES › CVE-2021-1870

CVE-2021-1870

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-1870 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatchedransomware

Apple's WebKit in iOS, iPadOS, and macOS had a remote code execution vulnerability that was actively exploited in the wild.

A logic flaw in WebKit allowed remote attackers to execute arbitrary code on affected Apple devices and systems relying on WebKit. This failure is critical for DIB organizations because it represents an unpatched, actively exploited vulnerability that could compromise endpoint security and violate CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations must ensure all WebKit-based applications and operating systems are patched immediately and monitor for similar exploits in the supply chain.

Shame score — The vulnerability was actively exploited in the wild (KEV) and linked to ransomware campaigns, indicating a severe failure in patch management and vulnerability mitigation that directly impacts endpoint security and compliance posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Significant negative impact due to exploitation and former employee involvement.
finance.yahoo.com ↗ severe-fallout -1.00
Damning report highlighting exploitation by a former employee.
"Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI"
cooey ↗ severe-fallout -0.50
Neutral reporting of the technical vulnerability.
"Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code."
xposedornot.com ↗ severe-fallout +0.00
No sentiment expressed, simply lists the CVE.
www.cvefind.com ↗ severe-fallout +0.00
No sentiment expressed, simply lists the CVE.
app.opencve.io ↗ severe-fallout +0.00
No sentiment expressed, simply lists the CVE.
cvefeed.io ↗ severe-fallout +0.00
No sentiment expressed, simply lists the CVE.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.