EXPOSURES › CVE-2021-30858
CVE-2021-30858
HIGH ⌖ ON CISA KEV · EXPLOITEDApple's iOS, iPadOS, and macOS WebKit contained a use-after-free vulnerability allowing remote code execution via malicious web content.
A use-after-free flaw in WebKit enabled attackers to execute arbitrary code by processing crafted web pages, directly impacting Safari and other WebKit-based browsers. Defense contractors must ensure all endpoints run patched OS versions to prevent remote compromise and maintain compliance with NIST 800-171's vulnerability management requirements. Organizations should enforce strict update policies and monitor for exploitation attempts targeting WebKit-based applications.
Shame score — A critical use-after-free flaw in a core browser engine was actively exploited in the wild, demonstrating severe negligence in patching a high-impact vulnerability that could lead to remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
"Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content."