CVE-2021-1879KEV · OVERDUE

Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

Medium · published April 2, 2021

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 6.1. It is confirmed in active exploitation. It sits in the 93.8th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
6.1
EPSS
7%
Percentile
93.8
In the wild
Confirmed
What it is

⚠️ A crafty exploit lurking in Apple’s web content handling could lead to universal cross-site scripting! 🚨 Think of it like a menu that lets diners order anything, even items that aren't on it. If the kitchen doesn’t check properly, they might whip up a dish that causes chaos instead of satisfaction! An attacker could deliver malicious scripts to devices, allowing them to steal sensitive information, track user activities, or even take control of web sessions. While it's not a total disaster, it’s certainly a nasty surprise for unsuspecting users!

Put simply

Think of it like a menu that lets diners order anything, even items that aren't on it. If the kitchen doesn’t check properly, they might whip up a dish that causes chaos instead of satisfaction! This vulnerability occurs due to improper management of object lifetimes while processing crafted web content, which can lead to unintended execution of scripts in the context of the user’s session.

What to do

An attacker could deliver malicious scripts to devices, allowing them to steal sensitive information, track user activities, or even take control of web sessions. While it's not a total disaster, it’s certainly a nasty surprise for unsuspecting users! Update your devices to iOS 12.5.2, iOS 14.4.2, iPadOS 14.4.2, or watchOS 7.3.3 immediately to shield against this vulnerability. Regularly check for updates to stay protected against newly discovered exploits. 🛡️ You've got this! Keep your devices updated and secured, and you'll be a security champion in no time! 🔒

The record
Technical detail
CVSS v3.1
6.1 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.07082 · 93.8th percentile
Published
2021-04-02T18:07Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 02 APR 18:07Z
    This issue was addressed by improved management of object lifetimes
    cvelistv5