First published: Mon Jun 14 2021(Updated: )
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
Credit: product-security@apple.com an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPhone OS | <12.5.4 | |
Apple iOS | <12.5.4 | 12.5.4 |
Apple iOS | ||
<12.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30762 is a use-after-free vulnerability in Apple iOS WebKit.
CVE-2021-30762 may allow for code execution when processing maliciously crafted web content on Apple iOS.
Apple iOS versions up to but excluding 12.5.4 are affected by CVE-2021-30762.
Update your Apple iOS device to version 12.5.4 to mitigate the impact of CVE-2021-30762.
You can find more information about CVE-2021-30762 on the Apple support website: https://support.apple.com/en-us/HT212548.