CVE-2021-1870
Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
Description
CVE-2021-1870 is a critical-severity logic vulnerability in Apple WebKit affecting iOS, iPadOS, and macOS. The flaw allows a remote attacker to cause arbitrary code execution by exploiting a logic issue in WebKit's restriction handling. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With a CVSS score of 9.8 and an EPSS score of 1.15% (78.3rd percentile), CVE-2021-1870 represents a maximum-risk remote code execution threat that also impacts WebKitGTK and Fedora Linux distributions.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| apple | ipados | < 14.4 |
| apple | iphone os | < 14.4 |
| apple | mac os x | >= 10.15, < 10.15.7; 10.15.7 |
| apple | macos | >= 11.0.1, < 11.2 |
| webkitgtk | webkitgtk | < 2.30.6 |
| fedoraproject | fedora | 32; 33 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN6ZOD62CTO54CHTMJTHVEF6R2Y532TJ/(Broken Link, Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3L6ZZOU5JS7E3RFYGLP7UFLXCG7TNLU/(Broken Link, Mailing List)
- https://security.gentoo.org/glsa/202104-03(Third Party Advisory)
- https://support.apple.com/en-us/HT212146(Release Notes, Vendor Advisory)
- https://support.apple.com/en-us/HT212147(Release Notes, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1870(US Government Resource)
Weakness Type
Logic Issue in WebKit
This vulnerability stems from a logic flaw in WebKit's restriction handling mechanisms. The issue was not assigned a specific CWE by NVD. Logic issues occur when the application's control flow or decision-making processes contain flaws that allow unintended behavior, in this case enabling remote code execution through crafted web content.
Learn more: NVD — CVE-2021-1870
Impact Analysis
CVE-2021-1870 carries a CVSS 3.1 score of 9.8 (CRITICAL), the near-maximum severity rating, indicating an extremely dangerous vulnerability. The flaw is remotely exploitable over the network with low attack complexity and requires no authentication or user interaction, making it trivially exploitable by any network-adjacent or remote attacker. Successful exploitation results in high impact to confidentiality, integrity, and availability, granting the attacker arbitrary code execution capabilities. The EPSS score of 1.15% (78.3rd percentile) indicates a notable probability of exploitation. Apple has acknowledged that this issue may have been actively exploited, and the broad affected product range including Apple platforms and Linux WebKitGTK amplifies the risk.
Exploit Maturity
CVE-2021-1870 is confirmed as actively exploited through its inclusion in the CISA Known Exploited Vulnerabilities catalog. Apple has acknowledged reports that this issue may have been actively exploited in the wild. The EPSS score of 1.15% (78.3rd percentile) indicates a meaningful probability of exploitation. No dedicated public exploit code was identified in the available references, though the vulnerability's critical severity and zero-interaction requirements make it highly attractive to attackers. Federal agencies were required to remediate by 2021-11-17 per CISA's binding operational directive.
Remediation
- Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. Update to iOS 14.4/iPadOS 14.4 and macOS Big Sur 11.2, or apply Security Update 2021-001 Catalina/Mojave for older macOS versions.
- For Linux systems using WebKitGTK, update to version 2.30.6 or later. Fedora users should apply all available security updates for their distribution version.
- Implement network-level web content filtering to restrict access to untrusted or suspicious web domains, reducing the likelihood of encountering malicious content that exploits this WebKit logic vulnerability.
- Monitor browser and WebKit-based application processes for signs of exploitation, including unexpected child processes, anomalous network connections, or unusual memory allocation patterns.
- Consider deploying browser isolation technologies or sandboxed browsing environments for high-risk users to contain the impact of potential WebKit exploitation.
Technical Details
CVE-2021-1870 is a logic vulnerability in Apple's WebKit rendering engine that results from insufficient restrictions in the engine's processing logic. According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the vulnerability is network-accessible with low complexity, requires no privileges and no user interaction, representing the most exploitable configuration possible. The logic issue allows a remote attacker to bypass intended restrictions in WebKit, ultimately achieving arbitrary code execution. This vulnerability affects not only Apple platforms but also WebKitGTK (< 2.30.6) used on Linux systems. Apple addressed the flaw with improved restrictions in macOS Big Sur 11.2, iOS 14.4, and iPadOS 14.4.
Frequently Asked Questions
Is CVE-2021-1870 being actively exploited?
Yes. CVE-2021-1870 is listed in the CISA Known Exploited Vulnerabilities catalog, and Apple has acknowledged reports of active exploitation in the wild. The EPSS score of 1.15% (78.3rd percentile) confirms a notable exploitation probability.
What products are affected by CVE-2021-1870?
CVE-2021-1870 affects Apple iPhone OS (< 14.4), iPadOS (< 14.4), Mac OS X (>= 10.15, < 10.15.7; 10.15.7), macOS (>= 11.0.1, < 11.2), WebKitGTK (< 2.30.6), and Fedora Linux (32; 33).
How do I fix CVE-2021-1870?
Apply updates per vendor instructions. Update Apple devices to iOS 14.4, iPadOS 14.4, or macOS Big Sur 11.2. For older macOS, apply Security Update 2021-001. Linux users should update WebKitGTK to version 2.30.6 or later.
How severe is CVE-2021-1870?
CVE-2021-1870 has a CVSS 3.1 score of 9.8 (CRITICAL). It requires no authentication and no user interaction for remote exploitation, making it one of the most dangerous WebKit vulnerabilities with confirmed active exploitation.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.