Vulnerability record · CVE-2021-30666 · published 8 September 2021
CVE-2021-30666: Apple iOS WebKit buffer overflow allows arbitrary code execution
Apple · Iphone Os
A memory buffer overflow in Apple iOS WebKit is triggered by processing maliciously crafted web content and was fixed in iOS 12.5.3. Apple stated it was aware of a report that the issue may have been actively exploited, making it a real-world risk to unpatched devices.
Description
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCISA KEV listing and Apple's acknowledgement of possible active exploitation raise urgency, though the CVSS score is 8.8 and EPSS is modest.
What it is
A memory buffer overflow in Apple iOS WebKit is triggered by processing maliciously crafted web content and was fixed in iOS 12.5.3. Apple stated it was aware of a report that the issue may have been actively exploited, making it a real-world risk to unpatched devices.
Impact
An attacker can achieve arbitrary code execution in the context of the affected WebKit process, potentially leading to full compromise of the device depending on the exploit chain. The CVSS vector indicates high confidentiality, integrity, and availability impact.
Attack surface
The flaw is reachable over the network via malicious web content rendered by WebKit, requiring user interaction such as visiting a crafted page. No authentication or privileges are needed on the target device.
Exploitation
The vulnerability is listed in CISA KEV with a due date of 2021-11-17, and Apple acknowledged possible active exploitation. EPSS probability is about 3% for the next 30 days, but KEV status confirms observed exploitation activity.
What to do
- Update affected Apple devices to iOS 12.5.3 or later as directed by Apple.
- Prioritize patching for devices that cannot be upgraded beyond iOS 12, since this fix targets that branch.
- Enforce web content filtering or disable JavaScript in high-risk browsing contexts where feasible.
- Monitor vendor advisories for any follow-up patches or additional affected versions.
Detection
- Hunt for iOS devices reporting versions below 12.5.3 in MDM or asset inventory.
- Review web proxy or DNS logs for access to known exploit-hosting domains if threat intelligence is available.
- Correlate unusual crashes or memory corruption reports from WebKit or Safari on unpatched devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30666 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apple iOS WebKit Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT212341 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT212341 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30666 | Third Party AdvisoryUS Government Resource |
Track CVE-2021-30666 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30666), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.