Vulnerability record · CVE-2021-30952 · published 24 August 2021
CVE-2021-30952: Apple WebKit integer overflow allows code execution via crafted web content
Apple · Safari
An integer overflow in Apple's WebKit engine was fixed by improved input validation across tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS/iPadOS 15.2 and watchOS 8.3, with WebKitGTK and WPE WebKit also affected. Processing maliciously crafted web content can lead to arbitrary code execution, making it a browser-engine memory-safety flaw with broad reach across Apple platforms and Linux WebKit ports.
Description
An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows arbitrary code execution from crafted web content and is in CISA KEV with an exploit-tagged reference, though it requires user interaction and is fixed by widely available updates.
What it is
An integer overflow in Apple's WebKit engine was fixed by improved input validation across tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS/iPadOS 15.2 and watchOS 8.3, with WebKitGTK and WPE WebKit also affected. Processing maliciously crafted web content can lead to arbitrary code execution, making it a browser-engine memory-safety flaw with broad reach across Apple platforms and Linux WebKit ports.
Impact
An attacker who gets a victim to load crafted web content can execute arbitrary code in the context of the affected browser or WebKit-based application, with high confidentiality, integrity and availability impact per the CVSS vector.
Attack surface
Reached by processing maliciously crafted web content, so the vector is local (AV:L) with user interaction required (UI:R) and no privileges needed (PR:N); in practice this means a victim must open or view attacker-controlled web content in a vulnerable WebKit-based browser or app.
Exploitation
CVE-2021-30952 is listed in CISA KEV with a due date of 2026-03-26, and a reference is tagged Exploit (Google Threat Intelligence on the Coruna iOS exploit kit), indicating known exploitation; EPSS 30-day probability is about 6.96 percent (93.8th percentile).
What to do
- Update to the fixed versions: iOS/iPadOS 15.2, macOS Monterey 12.1, tvOS 15.2, watchOS 8.3 and Safari 15.2, or later.
- Apply the corresponding WebKitGTK and WPE WebKit updates, and Debian DSA-5060/DSA-5061 and Fedora package updates for Linux deployments.
- Follow CISA KEV required action and BOD 22-01 guidance; discontinue use of affected products if mitigations are unavailable.
- Restrict or sandbox WebKit-based browsing and embedded web views on unpatched endpoints to reduce exposure to crafted content.
- Block or filter known exploit-kit delivery paths and untrusted web content reaching vulnerable WebKit clients.
Detection
- Hunt for WebKit-based processes (Safari, WebKit, WebKitWebProcess, WPE) spawning unexpected child processes or making anomalous outbound connections.
- Monitor for crashes or memory corruption indicators in WebKit processes correlated with visits to untrusted or newly registered domains.
- Review proxy and DNS logs for known exploit-kit infrastructure and suspicious content delivery to Apple or WebKitGTK clients.
- Track endpoint patch state for the fixed OS and WebKit versions and alert on hosts still running vulnerable builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-30952 to the Known Exploited Vulnerabilities catalog on 5 March 2026 as "Apple Multiple Products Integer Overflow or Wraparound Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 March 2026.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-30952 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30952), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.