668
VMScore

CVE-2021-1871

Published: 02/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A security issue exists in WebKitGTK prior to 2.32.0 and WPE WebKit prior to 2.32.0. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x

apple mac os x 10.15.7

apple iphone os

apple ipad os

apple macos

debian debian linux 10.0

fedoraproject fedora 33

Vendor Advisories

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2021-1788 Francisco Alonso discovered that processing maliciously crafted web content may lead to arbitrary code execution CVE-2021-1844 Clement Lecigne and Alison Huffman discovered that processing maliciously crafted web content may lead to arbi ...
A security issue was discovered in WebKitGTK before 2320 and WPE WebKit before 2320 A remote attacker may be able to cause arbitrary code execution Apple is aware of a report that this issue may have been actively exploited ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2021-01-26-1 iOS 144 and iPadOS 144 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Prod ...

Recent Articles

Apple emits emergency iOS security updates while warning holes may have been exploited in wild by hackers
The Register • Chris Williams, Editor in Chief • 26 Jan 2021

Plus fixes for iPadOS, tvOS, watchOS, XCode, iCloud for Windows – and a day after Google disclosed Nork op

Apple today released software updates to patch vulnerabilities in iPhones and iPads that may have been exploited by miscreants to silently snoop on victims from afar. Folks should check for and install the latest version of their iOS, iPadOS, watchOS, and tvOS software. Here's the quick run down of the programming blunders: CVE-2021-1782: Fixed in iOS 14.4 and iPadOS 14.4, available for iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation). This kernel...