CVE-2021-1879
בינונית 6.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 7% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-79
מוצרים מושפעים
apple: ipados; apple: iphone os; apple: watchos
קישורים
- https://support.apple.com/en-us/HT212256 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212257 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212258 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212256 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212257 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT212258 Release NotesVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource