SecPod

Learn Search

Search across all Learn content

← Back to Security Research

Apple Fixes Critical Zero-Day Flaws

Apple released May 2021 zero-day exploit security updates for multiple products, including Safari, macOS, iOS, iPadOS, tvOS and watchOS. Apple Zero Day Exploit of some of these security flaws will allow an attacker to take control of the victim’s system and put Mac users at great risk. However, a vu

May 5, 20212 min read

Apple released May 2021 zero-day exploit security updates for multiple products, including Safari, macOS, iOS, iPadOS, tvOS and watchOS. Apple Zero Day Exploit of some of these security flaws will allow an attacker to take control of the  victim’s system and put Mac users at great risk. However, a vulnerability management tool can mitigate these.

The updates for Apple products include fixes for 4 vulnerabilities, including two zero-days. These flaws allow attackers to corrupt memory, execute arbitrary code, and even control the affected device. All these flaws are observed to be actively exploited by attackers. To avoid these flaws, we can use a patch management tool.

Zero-Day ( CVE-2021-30665 )

A critical zero-day vulnerability residing in the Webkit browser engine of iOS is fixed in this May update. The vulnerability is due to a memory corruption issue related to improper state management. Also, the vulnerability allows an attacker to remotely execute commands on vulnerable devices simply by visiting a malicious website. The vulnerability is discovered and reported by security researchers from China. The new release of 14.5.1 is mitigating this issue along with other bugs.

Zero-Day ( CVE-2021-30663 )

One more critical zero-day vulnerability residing in the Webkit browser rendering engine of iOS is also fixed in this security update. The vulnerability is due to an integer overflow issue related to improper input validation. It allows attackers to conduct remote code execution on iPhones, iPads, iPods, macOS, and Apple Watch devices. An anonymous source is behind the discovery of this 0-day.

Apple Security Updates Summary for May 2021

macOS

Safari

iOS and iPadOS

  • Product: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
  • Affected features: WebKit
  • Impact: Arbitrary code execution
  • CVEs: CVE-2021-30665, CVE-2021-30663

iOS

watchOS

  • Product: Apple Watch Series 3 and later
  • Affected features: WebKit
  • Impact: Arbitrary code execution
  • CVEs: CVE-2021-30665

Moreover, Apple Zero Day Exploit affected these products.

Also, SanerNow detects these vulnerabilities and automatically fixes them by applying security updates. Furthermore, Use SanerNow to keep your systems updated and secure.

Featured Posts

Open Top Vulnerability Scanning Tools 2024

Top Vulnerability Scanning Tools 2024

CVE Research

Top Vulnerability Scanning Tools 2024

According to statistics, a new cyberattack was detected every 39 seconds in 2023! With this rise in number of attacks, protecting sensitive data becomes crucial and challenging. To protect IT, vulnerability scanners are the lead at defense, actively identifying weaknesses within systems and networks

Sep 17, 2026

Open The Webm Zero-Days: All Over The Wild

The Webm Zero-Days: All Over The Wild

CVE Research

The Webm Zero-Days: All Over The Wild

Webmproject, a popular media file format, has been experiencing hardships in security. Two of its libraries, libwebp and libvpx, have been found to contain zero-day vulnerabilities that affect multiple commonly used software products, such as Chrome, Edge, Tor, Telegram, and more! The two notorious

Sep 17, 2026

Open The Ultimate Vulnerability Assessment Checklist

The Ultimate Vulnerability Assessment Checklist

CVE Research

The Ultimate Vulnerability Assessment Checklist

Vulnerability assessment is the process of identifying and assessing vulnerabilities. It makes up for a significant chunk of vulnerability management, and vulnerability management relies heavily on it. Without properly assessing vulnerabilities, your vulnerability management program might fail to me

Sep 17, 2026

Open SCAP Feed Release : 02-Dec-2017

SCAP Feed Release : 02-Dec-2017

CVE Research

SCAP Feed Release : 02-Dec-2017

The following SCAP content has been released to SCAP Repo and SecPod Saner Solution. SecPod Saner will automatically pull the relevant content on its next scheduled update. oval:org.secpod.oval:def:42845 CVE-2017-11293 Out-of-bounds read vulnerability in Adobe Acrobat and Reader products via unspeci

Sep 17, 2026

Apple Fixes Critical Zero-Day Flaws | SecPod