FEDORA-2021-864dc37032Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3L6ZZOU5JS7E3RFYGLP7UFLXCG7TNLU CVE-2021-1871
CRITICALCISA KEV
Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
Record summary
CVE-2021-1871 has a selected CVSS score of 9.8 (critical). CISA lists CVE-2021-1871 in KEV.
Description
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Jan 26, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 14.4 | affected |
iOS, iPadOS, and macOSBrowse Apple / iOS, iPadOS, and macOS | CISA | Version data not supplied | |
macOSBrowse Apple / macOS | CVE List | Before 11.2 | affected |
References
7lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L3L6ZZOU5JS7E3RFYGLP7UFLXCG7TNLU nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-1871 support.apple.com
https://support.apple.com/en-us/HT212146 support.apple.com
https://support.apple.com/en-us/HT212147 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1871 DSA-4923Vendor advisory
https://www.debian.org/security/2021/dsa-4923