EXPOSURES › CVE-2021-1879
CVE-2021-1879
HIGH ⌖ ON CISA KEV · EXPLOITEDWebKit XSS vulnerability in Apple iOS, iPadOS, and watchOS allows universal cross-site scripting when processing malicious web content.
This XSS flaw in WebKit impacts Apple Safari and other products relying on WebKit for HTML processing, enabling attackers to inject malicious scripts into web pages. DIB organizations must ensure their mobile device management policies enforce timely OS updates to prevent script injection attacks that could compromise sensitive data or bypass security controls. The vulnerability was actively exploited in the wild, highlighting the risk of relying on third-party components like WebKit without rigorous supply chain validation.
Shame score — A high-severity, actively exploited XSS vulnerability in a widely used component like WebKit demonstrates significant negligence in patching and supply chain security, especially given its inclusion in the CISA KEV catalog.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
"Langflow's CVE-2026-55255 let an authenticated attacker execute another user's AI workflow…"
"This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing."
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
"CVEs and Security Vulnerabilities - OpenCVE"
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
"Browse our complete data breach directory, built from the XposedOrNot database."