Skip to content
COOEY

EXPOSURES › CVE-2021-30858

CVE-2021-30858

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30858 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Apple's iOS, iPadOS, and macOS WebKit contained a use-after-free vulnerability allowing remote code execution via malicious web content.

A use-after-free flaw in WebKit enabled attackers to execute arbitrary code by processing crafted web pages, directly impacting Safari and other WebKit-based browsers. Defense contractors must ensure all endpoints run patched OS versions to prevent remote compromise and maintain compliance with NIST 800-171's vulnerability management requirements. Organizations should enforce strict update policies and monitor for exploitation attempts targeting WebKit-based applications.

Shame score — A critical use-after-free flaw in a core browser engine was actively exploited in the wild, demonstrating severe negligence in patching a high-impact vulnerability that could lead to remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; sources are CVE databases or unrelated advisories.
cooey ↗ neutral +0.00
Neutral; NVD summary only states facts.
"Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content."
www.cvefind.com ↗ neutral +0.00
Neutral; CVE database listing with no commentary.
Neutral; Cisco advisory unrelated to CVE-2021-30858.
app.opencve.io ↗ neutral +0.00
Neutral; OpenCVE database listing with no commentary.
SentinelOne ↗ neutral +0.00
Neutral; SentinelOne landing page with no commentary.
sam.gov ↗ neutral +0.00
Neutral; SAM.gov contract page with no commentary.
cve.akaoma.com ↗ neutral +0.00
Neutral; Akaoma CVE dashboard with no commentary.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.