
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-30954 is a type confusion vulnerability discovered in WebKit, affecting multiple Apple products including tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2, iPadOS 15.2, and watchOS 8.3. The vulnerability was discovered by Kunlun Lab and was disclosed through the Tianfu Cup. The issue was fixed in December 2021 with the release of security updates for the affected systems (Apple Support).
The vulnerability is classified as a type confusion issue in WebKit that was addressed with improved memory handling. It has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD). The vulnerability is tracked under CWE-843: Access of Resource Using Incompatible Type ('Type Confusion').
When exploited, processing maliciously crafted web content may lead to arbitrary code execution on affected systems (Apple Support, Debian Security).
Apple addressed this vulnerability by releasing security updates for all affected systems: tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2, iPadOS 15.2, and watchOS 8.3. Additionally, Debian released security updates for webkit2gtk (version 2.34.4-1~deb11u1) and wpewebkit packages (Debian Security, Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."