Vulnerability record · CVE-2021-30661 · published 8 September 2021
CVE-2021-30661: Apple WebKit use-after-free allows code execution via crafted web content
Apple · Safari
A use-after-free flaw in Apple's WebKit was fixed through improved memory management across Safari, iOS, iPadOS, watchOS, tvOS and macOS. Processing maliciously crafted web content can lead to arbitrary code execution, and Apple stated it was aware of a report that the issue may have been actively exploited.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution with only user interaction and is confirmed as exploited in the wild per CISA KEV and Apple's advisory.
What it is
A use-after-free flaw in Apple's WebKit was fixed through improved memory management across Safari, iOS, iPadOS, watchOS, tvOS and macOS. Processing maliciously crafted web content can lead to arbitrary code execution, and Apple stated it was aware of a report that the issue may have been actively exploited.
Impact
An attacker can execute arbitrary code in the context of the affected browser or web content process, potentially gaining control of the device or user data. The CVSS vector rates confidentiality, integrity and availability impacts as high.
Attack surface
Reached over the network by rendering maliciously crafted web content; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so a victim must load the content, typically by visiting a page or opening a link.
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog with a 2021-11-03 addition date, and Apple stated it was aware of a report of active exploitation; EPSS 30-day probability is about 4.5 percent (90.9th percentile).
What to do
- Apply the vendor updates referenced in Apple advisories HT212317, HT212318, HT212323, HT212324, HT212325 and HT212341 (Safari 14.1, iOS 12.5.3, iOS/iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3) per CISA's required action.
- Prioritize patching internet-facing and user-facing Apple devices, especially those used for browsing or email, given known exploitation.
- Enforce current browser and OS versions through managed update policies and verify compliance on endpoints.
- Reduce exposure by restricting browsing to trusted sites and blocking known malicious domains where feasible.
Detection
- Monitor for crashes or abnormal terminations of WebKit, Safari and related web content processes on Apple devices.
- Hunt for unexpected child processes or code execution spawned from browser or web content processes.
- Review web proxy and DNS logs for access to known exploit-hosting or malicious domains tied to WebKit exploitation.
- Track endpoint telemetry for post-exploitation behavior on patched versus unpatched Apple devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30661 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apple Multiple Products WebKit Storage Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT212317 | Vendor Advisory |
| https://support.apple.com/en-us/HT212318 | Vendor Advisory |
| https://support.apple.com/en-us/HT212323 | Vendor Advisory |
| https://support.apple.com/en-us/HT212324 | Vendor Advisory |
| https://support.apple.com/en-us/HT212325 | Vendor Advisory |
| https://support.apple.com/en-us/HT212341 | Vendor Advisory |
| https://support.apple.com/en-us/HT212317 | Vendor Advisory |
| https://support.apple.com/en-us/HT212318 | Vendor Advisory |
| https://support.apple.com/en-us/HT212323 | Vendor Advisory |
| https://support.apple.com/en-us/HT212324 | Vendor Advisory |
| https://support.apple.com/en-us/HT212325 | Vendor Advisory |
| https://support.apple.com/en-us/HT212341 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30661 | Third Party AdvisoryUS Government Resource |
Track CVE-2021-30661 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30661), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.