6.8
CVSSv2

CVE-2021-30749

Published: 08/09/2021 Updated: 15/09/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

This vulnerability allows remote malicious users to execute arbitrary code on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the KeyframeEffect class. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

apple ipad os

apple iphone os

apple mac os

apple tvos

apple watchos

Vendor Advisories

No description is available for this CVE ...
A security issue has been found in WebKitGTK and WPE WebKit before 2323 Processing maliciously crafted web content may lead to arbitrary code execution ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security updates page Apple security documents reference vulnerabilities by CVE-ID when possible ...
The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2021-21775 Marcin Towalski discovered that a specially crafted web page can lead to a potential information leak and further memory corruption In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage CVE-2 ...
Arch Linux Security Advisory ASA-202107-68 ========================================== Severity: High Date : 2021-07-27 CVE-ID : CVE-2021-21775 CVE-2021-21779 CVE-2021-30663 CVE-2021-30665 CVE-2021-30689 CVE-2021-30720 CVE-2021-30734 CVE-2021-30744 CVE-2021-30749 CVE-2021-30795 CVE-2021-30797 CVE-2021-30799 Package : wpewebk ...
Arch Linux Security Advisory ASA-202107-67 ========================================== Severity: High Date : 2021-07-27 CVE-ID : CVE-2021-21775 CVE-2021-21779 CVE-2021-30663 CVE-2021-30665 CVE-2021-30689 CVE-2021-30720 CVE-2021-30734 CVE-2021-30744 CVE-2021-30749 CVE-2021-30795 CVE-2021-30797 CVE-2021-30799 Package : webkit2 ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-5 Safari 1411 Safari 1411 addresses the following issues Information about the security content is also available at supportapplecom/HT212534 WebKit Available for: macOS Catalina and macOS Mojave Impact: Processing maliciously crafted web content may lead to arbi ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-7 tvOS 146 tvOS 146 addresses the following issues Information about the security content is also available at supportapplecom/HT212532 Audio Available for: Apple TV 4K and Apple TV HD Impact: Processing a maliciously crafted audio file may lead to arbitrary code e ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-6 watchOS 75 watchOS 75 addresses the following issues Information about the security content is also available at supportapplecom/HT212533 Audio Available for: Apple Watch Series 3 and later Impact: Processing a maliciously crafted audio file may lead to arbitrary ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-1 iOS 146 and iPadOS 146 iOS 146 and iPadOS 146 addresses the following issues Information about the security content is also available at supportapplecom/HT212528 Audio Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th gen ...
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2021-0004 ------------------------------------------------------------------------ Date reported : July 23, 2021 Advisory ID : WSA-2021-0004 WebKitGTK Advisory URL : webkitgtkorg/se ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-05-25-2 macOS Big Sur 114 macOS Big Sur 114 addresses the following issues Information about the security content is also available at supportapplecom/HT212529 AMD Available for: macOS Big Sur Impact: A remote attacker may be able to cause unexpected application terminat ...