First published: Mon May 03 2021(Updated: )
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Credit: product-security@apple.com yangkang &zerokeeper&bianliang @dnpushme 360 ATA product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <12.5.3 | |
Apple iOS | <12.5.3 | 12.5.3 |
Apple iOS | ||
<12.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30666 is a buffer-overflow vulnerability in Apple iOS WebKit.
CVE-2021-30666 may allow for code execution when processing maliciously crafted web content on Apple iOS.
Users of Apple iOS versions up to and including 12.5.3 are affected by CVE-2021-30666.
CVE-2021-30666 is a buffer-overflow vulnerability that can potentially lead to code execution.
To fix CVE-2021-30666, users should update their Apple iOS to version 12.5.4 or later.