CVE-2021-1870KEV · OVERDUE

Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Critical · published April 2, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 94.2th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
8%
Percentile
94.2
In the wild
Confirmed
What it is

🚨 A remote attacker can trigger arbitrary code execution in macOS and iOS devices! This is a critical issue you absolutely need to address! 🔥 Think of this like a sneaky intruder who finds a loophole in your home security system, allowing them to waltz right in and take over your smart devices without you even knowing. It’s a perfect example of how tiny access flaws can lead to major security breaches! If exploited, this vulnerability could allow attackers to run any code of their choice on your device, leading to data theft, unauthorized access, or even complete control of your systems! The potential fallout could be absolutely devastating for your personal and sensitive information. 🔥

Put simply

Think of this like a sneaky intruder who finds a loophole in your home security system, allowing them to waltz right in and take over your smart devices without you even knowing. It’s a perfect example of how tiny access flaws can lead to major security breaches! This logic flaw in Apple’s systems allows a remote attacker to bypass restrictions and execute arbitrary code. The issue has been actively exploited, meaning it poses a real and present danger to users.

What to do

If exploited, this vulnerability could allow attackers to run any code of their choice on your device, leading to data theft, unauthorized access, or even complete control of your systems! The potential fallout could be absolutely devastating for your personal and sensitive information. 🔥 To protect yourself, immediately update your devices to macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, or iOS/iPadOS 14.4. Make sure to check for updates regularly to stay one step ahead! You've got this! By following these steps, you can lock down your devices and ensure you're safe from lurking threats. 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.07710 · 94.2th percentile
Published
2021-04-02T18:06Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 02 APR 18:06Z
    A logic issue was addressed with improved restrictions
    cvelistv5