Vulnerability record · CVE-2021-1789 · published 2 April 2021
CVE-2021-1789: Apple WebKit type confusion allows code execution via crafted web content
Apple · Ipados
A type confusion flaw in Apple's WebKit engine was fixed through improved state handling across macOS, iOS, iPadOS, tvOS, watchOS and Safari. Processing maliciously crafted web content can lead to arbitrary code execution, making it a serious browser-engine bug affecting a very wide install base.
Description
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA's KEV catalog with confirmed in-the-wild exploitation and a high CVSS score of 8.8, though it requires user interaction and patches have long been available.
What it is
A type confusion flaw in Apple's WebKit engine was fixed through improved state handling across macOS, iOS, iPadOS, tvOS, watchOS and Safari. Processing maliciously crafted web content can lead to arbitrary code execution, making it a serious browser-engine bug affecting a very wide install base.
Impact
An attacker can achieve arbitrary code execution in the context of the affected component when a victim loads crafted web content, potentially leading to full compromise of the device or user data.
Attack surface
Reached over the network by delivering malicious web content to a browser or WebKit-based view; the CVSS vector indicates no privileges required but user interaction is required, meaning the victim must load or view the crafted content.
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-04), confirming exploitation in the wild; EPSS shows a 30-day probability of 0.14479 (96th percentile), indicating elevated likelihood. No ransomware campaign use is documented.
What to do
- Apply the vendor updates: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4, iPadOS 14.4 and Safari 14.0.3.
- Update WebKitGTK and Fedora packages to the fixed versions referenced in the vendor advisories.
- Prioritize patching internet-facing and user-browsing endpoints, since exploitation requires only viewing crafted web content.
- Where immediate patching is not possible, restrict browsing to trusted sites and enforce content filtering to reduce exposure to malicious web content.
Detection
- Monitor for crashes or abnormal process behavior in WebKit-based browsers and web views on unpatched Apple devices.
- Hunt for exploitation attempts via web proxy or DNS logs showing delivery of suspicious web content to Apple clients.
- Track endpoint versions against the fixed releases to identify unpatched macOS, iOS, iPadOS, tvOS, watchOS and Safari installs.
- Review CISA KEV remediation status to confirm patching within the required due date.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-1789 to the Known Exploited Vulnerabilities catalog on 4 May 2022 as "Apple Multiple Products Type Confusion Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 25 May 2022.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-1789 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-1789), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.