Actively Exploited in the Wild
This vulnerability is being actively exploited in the wild.
Apple WebKit Universal Cross-Site Scripting Vulnerability
Vulnerability
A universal cross-site scripting vulnerability has been identified in the WebKit component of Apple iOS, iPadOS, and watchOS. This issue arises from improper management of object lifetimes, allowing maliciously crafted web content to be processed in a way that could lead to cross-site scripting. The vulnerability has been reported to be actively exploited.
Impact
Exploitation of this vulnerability allows for universal cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Remediation
Users can update to iOS 12.5.2, iOS 14.4.2, iPadOS 14.4.2, or watchOS 7.3.3 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
