CVE-2021-1879
ENISA EUVD: EUVD-2021-7343 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
15 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.81%
probability
This CVE has a 0.81% probability
of being exploited in the next 30 days.
0%
Top 74.4th percentile of all CVEs
100%
CVSS v3.1
Source: NVD6.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
Project ZeroUniversal cross site scripting in Webkit
Affected Products
Attack Intelligence
Google Project Zero
Patched
March 26, 2021
Reported by
Clement Lecigne of Google Threat Analysis Group and Billy Leonard of Google Threat Analysis Group
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2021/CVE-2021-1879.html
Apple fixes a iOS zero-day vulnerability actively used in attacks
BleepingComputer
Mar 26, 2021
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Qualys
Oct 18, 2021
Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks
BleepingComputer
Oct 11, 2021
Apple fixes iOS zero-day used to deploy NSO iPhone spyware
BleepingComputer
Sep 13, 2021
Apple fixes zero-day affecting iPhones and Macs, exploited in the wild
BleepingComputer
Jul 26, 2021
Apple patches new zero-day bug used to hack iPhones and Macs
BleepingComputer
Sep 23, 2021
Apple fixes ninth zero-day bug exploited in the wild this year
BleepingComputer
Jun 15, 2021
Google: Russian SVR hackers targeted LinkedIn users with Safari zero-day
BleepingComputer
Jul 14, 2021
Apple fixes bug that breaks iPhone WiFi when joining rogue hotspots
BleepingComputer
Jul 23, 2021
Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors
BleepingComputer
Aug 29, 2024
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Signal Intelligence
Confidence
92%
EPSS
0.81%
CVSS v3.1
6.1
Mentions
15
Last Seen
Aug 29, 2024
CNA Information
Analyst Note
CVE-2021-1879 demonstrates strong confirmation signals including Apple's explicit acknowledgment of active exploitation, Google Project Zero inclusion, and documented real-world use by APT29. The vulnerability affects widely-deployed iOS/iPadOS platforms with fixed patches available, and the UXSS impact on web content processing represents a credible threat vector.
Triage Info
Decided atMar 03, 2026