« Volver al listado

CVE-2021-30661

Estado: AnalizadaAlta (8.8)⚠ Explotación activa

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Use-after-free (CWE-416) en Safari/navegadores requiere interacción del usuario (UI:R) para procesar contenido web malicioso, permitiendo ejecución de código arbitrario. Explotación activa confirmada.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-30661",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-30661",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-29T17:25:03.198561Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "14.5",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "Safari",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "14.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "tvOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "14.5",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "watchOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "7.4",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "11.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "12.5",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-09-08T15:15:13.320",
  "references": [
    {
      "url": "https://support.apple.com/en-us/HT212317",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212318",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212323",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212324",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212325",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212341",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/HT212317",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212318",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212323",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212324",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212325",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT212341",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30661",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "lang": "es",
      "value": "Se abordó un problema de uso de la memoria previamente liberada con una administración de la memoria mejorada. Este problema es corregido en Safari versión 14.1, iOS versión 12.5.3, iOS versión 14.5 y iPadOS versión 14.5, watchOS versión 7.4, tvOS versión 14.5, macOS Big Sur versión 11.3. El procesamiento de contenido web maliciosamente diseñado puede conllevar a una ejecución de código arbitrario. Apple está al tanto de un informe de que este problema puede haber sido explotado activamente"
    }
  ],
  "lastModified": "2026-06-17T03:50:38.600",
  "cisaActionDue": "2021-11-17",
  "cisaExploitAdd": "2021-11-03",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42EAB49D-2EA1-4B1F-BDAC-3165D1CB3759",
              "versionEndExcluding": "14.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EAAE2C1-EF21-4567-99F1-335D1EF955D1",
              "versionEndExcluding": "14.5"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "443BF1FD-EC67-437D-A9CA-EEB3EF25B701",
              "versionEndExcluding": "12.5.3"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CB84E58-2162-4B65-BD9E-F59C26DD4A60",
              "versionEndExcluding": "14.5",
              "versionStartIncluding": "14.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E699CCC-31F5-458E-A59C-79B3AF143747",
              "versionEndExcluding": "11.3",
              "versionStartIncluding": "11.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5B77841-F161-47AB-8043-3E0346E3AA25",
              "versionEndExcluding": "14.5"
            },
            {
              "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFFFE00C-0AA6-4F60-ABF4-E68877BFD8F8",
              "versionEndExcluding": "7.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com",
  "cisaRequiredAction": "Apply updates per vendor instructions.",
  "cisaVulnerabilityName": "Apple Multiple Products WebKit Storage Use-After-Free Vulnerability"
}