Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-30952

70
FAUCET Score

CVE-2021-30952 is an integer overflow vulnerability, addressed by improved input validation, that affects Apple's iOS, macOS, tvOS, watchOS, and Safari, along with other WebKit-based software like WebKitGTK and WPE WebKit. With a CVSS score of 7.8 (High), this flaw enables arbitrary code execution through the processing of maliciously crafted web content, requiring user interaction but presenting low attack complexity and high impact on system confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's Known Exploited Vulnerabilities catalog and the Hot List, and has received significant community and media attention, despite no public exploit code being readily available.

Impacted Technologies

VendorProductVersion(s)CPE
< 15.2CPE matchmatch criteria
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
< 15.2CPE matchmatch criteria
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
< 15.2CPE matchmatch criteria
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
>= 12.0, < 12.1CPE matchmatch criteria
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
< 15.2CPE matchmatch criteria
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.62%
Probability of exploitation in next 30 days
EPSS Percentile
93.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 5, 2026
This CVE's current EPSS score of 0.0762 is in the 94th percentile among its peer group of 11,617 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: webkitgtk4-0:2.48.3-2.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: webkit2gtk3-0:2.34.6-1.el8
View patch
applevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2021-30952Moderate

webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution

Jan 21, 2022

References

cloud.google.com / blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit
ExploitThird Party Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/7EQVZ3CEMTINLBZ7PBC7WRXVEVCRHNSM
Broken Link
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HQKWD4BXRDD2YGR5AVU7H5J5PIQIEU6V
Broken Link
support.apple.com / en-us/HT212975
Release NotesVendor Advisory
support.apple.com / en-us/HT212976
Release NotesVendor Advisory
support.apple.com / en-us/HT212978
Release NotesVendor Advisory
support.apple.com / en-us/HT212980
Release NotesVendor Advisory
support.apple.com / en-us/HT212982
Release NotesVendor Advisory
debian.org / security/2022/dsa-5060
Mailing ListThird Party Advisory
debian.org / security/2022/dsa-5061
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/01/21/2
Mailing ListThird Party Advisory