← Back to browse · API

CVE-2021-1879

Severity
MEDIUM
CVSS
6.1
EPSS
0.06845
Risk score
51.8
CISA KEV
Yes
PoC
No
Published
2021-04-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-7343, GHSA-QHQP-QW35-F96R
Products
Apple:iOS and iPadOS unspecified <14.4, Apple:iOS, iPadOS, and watchOS, Apple:watchOS unspecified <7.3, Cisco:IOS unspecified <12.5
Sources
euvd EUVD-2021-7343
cisa.gov CVE-2021-1879

Description

This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..

References