Skip to content
COOEY

EXPOSURES › CVE-2021-1879

CVE-2021-1879

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-1879 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

WebKit XSS vulnerability in Apple iOS, iPadOS, and watchOS allows universal cross-site scripting when processing malicious web content.

This XSS flaw in WebKit impacts Apple Safari and other products relying on WebKit for HTML processing, enabling attackers to inject malicious scripts into web pages. DIB organizations must ensure their mobile device management policies enforce timely OS updates to prevent script injection attacks that could compromise sensitive data or bypass security controls. The vulnerability was actively exploited in the wild, highlighting the risk of relying on third-party components like WebKit without rigorous supply chain validation.

Shame score — A high-severity, actively exploited XSS vulnerability in a widely used component like WebKit demonstrates significant negligence in patching and supply chain security, especially given its inclusion in the CISA KEV catalog.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread reporting and inclusion in KEV databases indicate a significant security failure with potential for exploitation.
kev.5sn.com ↗ severe-fallout -0.90
Featured in analysis highlighting recurring failure patterns and potential for serious consequences.
"Langflow's CVE-2026-55255 let an authenticated attacker execute another user's AI workflow…"
cooey ↗ severe-fallout -0.80
Initial reporting highlights the severity and potential impact.
"This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing."
cvefeed.io ↗ severe-fallout -0.60
Acknowledges exploitation and highlights importance for remediation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
app.opencve.io ↗ severe-fallout +0.00
Neutral listing, no commentary.
"CVEs and Security Vulnerabilities - OpenCVE"
www.cvefind.com ↗ severe-fallout +0.00
Neutral listing, no commentary.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
xposedornot.com ↗ severe-fallout +0.00
Neutral listing, no commentary.
"Browse our complete data breach directory, built from the XposedOrNot database."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.