[oss-security] 20211220 WebKitGTK and WPE WebKit Security Advisory WSA-2021-0007mailing list
http://www.openwall.com/lists/oss-security/2021/12/20/6 CVE-2021-30809
HIGH
Record summary
CVE-2021-30809 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
SafariBrowse Apple / Safari | CVE List | Before 15 | affected |
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 15 | affected |
| CVE List | Before 15 | affected | |
watchOSBrowse Apple / watchOS | CVE List | Before 8 | affected |
Proofs of concept
1Repository PoCs
GitHubseregonwar/CVE-2021-30809-OOMRepository PoCby seregonwarStars: 4Not analyzed5 files
References
7nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-30809 support.apple.com
https://support.apple.com/en-us/HT212814 support.apple.com
https://support.apple.com/en-us/HT212815 support.apple.com
https://support.apple.com/en-us/HT212816 support.apple.com
https://support.apple.com/en-us/HT212819 support.apple.comConfirmation
https://support.apple.com/kb/HT212869