CVE-2021-1871
Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution.
Apple is aware of a report that this issue may have been actively exploited..
CRITICAL · CVSS 9.8
⚠ CISA KEV
EPSS 0.00484
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules8
YARA rules0