CVE-2021-1879: Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

Published Mar 26, 2021
·
Updated

Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Other sources

This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..

WebKit. This issue was addressed by improved management of object lifetimes.

Credit

Clement Lecigne(Google Threat Analysis Group), Billy Leonard(Google Threat Analysis Group), Clement Lecigne(Google Threat Analysis Group), Billy Leonard(Google Threat Analysis Group), Clement Lecigne(Google Threat Analysis Group), Billy Leonard(Google Threat Analysis Group)

Affected Software

9 affected componentsFixes available
Apple WatchOS<7.3.3
7.3.3
Apple iOS<12.5.2
12.5.2
Apple iOS, iPadOS, and watchOS
Apple iOS<14.4.2
14.4.2
Apple iPadOS<14.4.2
14.4.2
Apple iPadOS<14.4.2
Apple iPhone OS<12.5.2
Apple iPhone OS>=13.0<14.4.2
Apple WatchOS<7.3.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apple iOS, iPadOS, and watchOS to a version that resolves this vulnerability.

    Fixed in 7.3.3
  2. Upgrade

    Upgrade Apple iOS and iPadOS to a version that resolves this vulnerability.

    Fixed in 12.5.2
  3. Upgrade

    Upgrade Apple iOS and iPadOS to a version that resolves this vulnerability.

    Fixed in 14.4.2
  4. Upgrade

    Upgrade Apple iOS, iPadOS, and macOS to a version that resolves this vulnerability.

    Fixed in 14.4.2

Event History

Apr 2, 2021
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
Aug 29, 2024
News Published
via BleepingComputer·01:04 PM
News Published
via BleepingComputer·01:06 PM

Parent advisories

This vulnerability appears in the following advisories.

Peer vulnerabilities

Found alongside the following vulnerabilities.

Frequently Asked Questions

1

What is the severity of CVE-2021-1879?

The severity of CVE-2021-1879 is high.

2

How does CVE-2021-1879 affect Apple devices?

CVE-2021-1879 affects Apple iOS, iPadOS, and watchOS devices.

3

What is the recommended remedy for CVE-2021-1879?

The recommended remedy for CVE-2021-1879 is to update to Apple iOS, iPadOS, and watchOS versions 14.4.2, 12.5.2, or 7.3.3.

4

What is cross-site scripting (XSS) vulnerability?

Cross-site scripting (XSS) vulnerability is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.

5

Where can I find more information about CVE-2021-1879?

You can find more information about CVE-2021-1879 on the Apple support website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203