CVE-2021-30952
9.5 CISA KEVApple · Multiple Products (iOS, iPadOS, macOS, Safari, tvOS, watchOS)
Apple products contain an integer overflow vulnerability that allows unauthenticated attackers to achieve arbitrary code execution by processing maliciously crafted web content.
Executive summary
This critical integer overflow vulnerability in multiple Apple products is confirmed to be actively exploited in the wild, posing an immediate risk of arbitrary code execution.
Vulnerability
The vulnerability is an integer overflow flaw caused by insufficient input validation. An unauthenticated attacker can exploit this by enticing a user to process maliciously crafted web content, leading to arbitrary code execution on the target device.
Business impact
The CVSS score of 9.5 indicates a critical severity level, reflecting the potential for full system compromise. Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged in user, which can lead to complete data exfiltration, unauthorized access to sensitive information, and significant reputational or operational damage. Given the active exploitation observed in the wild, the business risk is extremely high.
Remediation
Immediate Action: Update all affected Apple devices and software to the patched versions: iOS 15.2, iPadOS 15.2, macOS Monterey 12.1, Safari 15.2, tvOS 15.2, or watchOS 8.3.
Proactive Monitoring: Monitor network traffic for unusual patterns associated with web browser activity and review system logs for signs of unexpected process execution or unauthorized application behavior.
Compensating Controls: While no direct virtual patch exists, ensure that endpoint protection solutions are active and that users are instructed to avoid suspicious web links or untrusted content.
Exploitation status
Public Exploit Available: Yes, public exploit code referencing this vulnerability has been catalogued on GitHub.
Analyst recommendation
Due to the confirmed active exploitation and the critical nature of the flaw, this vulnerability must be treated as a top priority for remediation. IT and security teams should immediately initiate the update process for all managed devices to the specified fixed versions. Delaying the application of these updates exposes the organization to a high probability of compromise.
More Apple CVEs
Sources
- support.apple.com
- support.apple.com
- support.apple.com
- support.apple.com
- support.apple.com
- [oss-security] 20220121 WebKitGTK and WPE WebKit Security Advisory WSA-2022-0001 Mailing list
- FEDORA-2022-25a98f5d55 Vendor advisory
- DSA-5061 Vendor advisory