Actively Exploited in the Wild
This vulnerability is being actively exploited in the wild.
Apple WebKit Remote Code Execution Vulnerability
Vulnerability
A logic vulnerability allowing remote code execution has been identified in the WebKit component of Apple iOS, iPadOS, and macOS. This issue arises from insufficient restrictions in the handling of web content, which could be exploited by a remote attacker. The vulnerability affects WebKitGTK, the version of WebKit used in GTK applications, including those on macOS and iOS. The flaw has been addressed in multiple Apple software updates, including macOS Big Sur 11.2, Security Update 2021-001 for Catalina, Security Update 2021-001 for Mojave, iOS 14.4, and iPadOS 14.4.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the affected system.
Remediation
Users can update to the latest version of macOS or iOS to address this vulnerability. Instructions for updating can be found on the Apple Support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
